Search CVE reports
1 – 6 of 6 results
CVE-2023-32307
Medium prioritySome fixes available 6 of 8
Sofia-SIP is an open-source SIP User-Agent library, compliant with the IETF RFC3261 specification. Referring to [GHSA-8599-x7rq-fr54](https://github.com/freeswitch/sofia-sip/security/advisories/GHSA-8599-x7rq-fr54), several other...
2 affected packages
sip4, sofia-sip
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
sip4 | — | Not affected | Not affected | Not affected | Not affected |
sofia-sip | — | Fixed | Fixed | Fixed | Fixed |
CVE-2023-22741
Medium prioritySofia-SIP is an open-source SIP User-Agent library, compliant with the IETF RFC3261 specification. In affected versions Sofia-SIP **lacks both message length and attributes length checks** when it handles STUN packets, leading to...
1 affected packages
sofia-sip
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
sofia-sip | — | Fixed | Fixed | Fixed | Fixed |
CVE-2022-47516
Medium priorityAn issue was discovered in the libsofia-sip fork in drachtio-server before 0.8.20. It allows remote attackers to cause a denial of service (daemon crash) via a crafted UDP message that leads to a failure of...
1 affected packages
sofia-sip
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
sofia-sip | — | Fixed | Fixed | Fixed | Fixed |
CVE-2022-31003
Medium prioritySome fixes available 4 of 5
Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, when parsing each line of a sdp message, `rest = record + 2` will access the memory behind `\0` and cause an out-of-bounds...
1 affected packages
sofia-sip
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
sofia-sip | — | Fixed | Fixed | Fixed | Fixed |
CVE-2022-31001
Medium prioritySome fixes available 4 of 5
Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, an attacker can send a message with evil sdp to FreeSWITCH, which may cause crash. This type of crash may be caused by...
1 affected packages
sofia-sip
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
sofia-sip | — | Fixed | Fixed | Fixed | Fixed |
CVE-2022-31002
Medium prioritySome fixes available 4 of 5
Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, an attacker can send a message with evil sdp to FreeSWITCH, which may cause a crash. This type of crash may be caused by a...
1 affected packages
sofia-sip
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
sofia-sip | — | Fixed | Fixed | Fixed | Fixed |