Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [SECURITY] [DSA 5431-1] sofia-sip security update

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [SECURITY] [DSA 5431-1] sofia-sip security update


Chronologisch Thread  
  • From: Moritz Muehlenhoff <jmm AT debian.org>
  • To: debian-security-announce AT lists.debian.org
  • Subject: [IT-SecNots] [SECURITY] [DSA 5431-1] sofia-sip security update
  • Date: Fri, 16 Jun 2023 14:44:18 +0000
  • Authentication-results: mail.piratenpartei.de; dkim=none; spf=none (mail.piratenpartei.de: domain of "bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org" has no SPF policy when checking 82.195.75.100) smtp.mailfrom="bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org"; dmarc=none
  • List-archive: https://lists.debian.org/msgid-search/ZIx1QvvbT5jfMlRq AT seger.debian.org
  • List-id: <debian-security-announce.lists.debian.org>
  • List-url: <http://lists.debian.org/debian-security-announce/>
  • Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Content-Type:MIME-Version:Message-ID:Subject:To:From:Date :Reply-To:Cc:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=ya0JQJ096cylsCKCpoMSOefwym1Nw0XIG2jrmb40Szk=; b=H1 QUQYlqwCGPuvYKZe1DT96gsnT8Ty37Py2ZTXNafOwfuXP0hLb5LJCKv/0tR72B1UcbF2LeSgbKBwJ ma/O71nabtOc0kBMq0oMoUOsE2sh6BR0dfspu2vtTvlbnus45Xd0HPE3+XrRum2e84XkSWsrAICjO AqoVc0T6PY719RCZPiPB1H41Z0sZkMjpSNp8wx0HecV6CKu00cF8dO0E08qRYqgdTO7QC6hjC4iDE SNFtqlqaB4Wl6C8jlJ+u1oGVh1KBNObMS53FtGREEgCC+mhJhIZTKsurx3GDhzpTaQHcmute7kXw8 5tjNCqQnUPgpwepZFv9Uu4qks7Wxq+zg==;
  • Old-return-path: <jmm AT seger.debian.org>
  • Priority: urgent
  • Resent-date: Fri, 16 Jun 2023 14:44:45 +0000 (UTC)
  • Resent-from: debian-security-announce AT lists.debian.org
  • Resent-message-id: <ybSa1bof3zL.A.cgC.dVHjkB@bendel>
  • Resent-sender: debian-security-announce-request AT lists.debian.org

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-5431-1 security AT debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
June 16, 2023 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : sofia-sip
CVE ID : CVE-2023-32307
Debian Bug : 1036847

Xu Biang discovered that missing input sanitising in Sofia-SIP, a SIP
User-Agent library could result in denial of service.

For the oldstable distribution (bullseye), this problem has been fixed
in version 1.12.11+20110422.1-2.1+deb11u2.

We recommend that you upgrade your sofia-sip packages.

For the detailed security status of sofia-sip please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/sofia-sip

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmSMdDMACgkQEMKTtsN8
TjYfkxAArFibANmIokupgYg4AFcFpZqsBQdg+eV2TeX3BRkTaj5UCimLyBZKPhmi
h/k27gp/F1Pn5GOVAltrNWUp83EENWDHcTlR6inmv2/IDFJZVbR8XIJhz+7FUfC2
aGh8bfgDGYM0C+/2BQzK4TmPPNRjnxRsbrBB+upNEJ6PlqDlktHeT3ks0VbQbGuZ
gUoJMMrSQoztYfFbJJNr5hAOQUxkxz8avoVC66YXGtntj+PvXiPIZQiIOrjylF2a
LdFvtbldjZXCeUn/7Iu+w8ekMM4skFmZ91JZ2AvMa1Mxmzp8MZ1KIpLnpLm34k7U
ZS9om0nBj5SschYywGmohPjyfAJUwtMhZmPp3h67UxdY3SrMYDnmrioX3+GJL6yP
opkgbW4eVUNkgxX2AkfEMblwYgB/ysiwmxSmkqRiG4FetseZZJ8h85Wn9q/TZrf8
yANBQbjmjXrjwv50fVuSApTV7lHsZWf79zOG8DZJikQ8/npdcDRFngZsH5NqD01G
3JSrYEUnI+oH+/XfdY7YFsmgpOifKp+19aYvbiv1SFLs6jOBTWhwJn7Gd9kiW6Iz
Tzu4ze2CmfzbOn9v4LdqMUodCO4/F77ahxHBblfKqNpy2bFWg/gyTtkY/MgG3PGB
6pQmvTzADqtjNFErvP4wUpfqXHoa4x/sIcRND75hOH03UJ3gLf4=
=EZ/C
-----END PGP SIGNATURE-----



  • [IT-SecNots] [SECURITY] [DSA 5431-1] sofia-sip security update, Moritz Muehlenhoff, 16.06.2023

Archiv bereitgestellt durch MHonArc 2.6.24.

Seitenanfang