Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, an attacker can send a message with evil sdp to FreeSWITCH, which may cause crash. This type of crash may be caused by `#define MATCH(s, m) (strncmp(s, m, n = sizeof(m) - 1) == 0)`, which will make `n` bigger and trigger out-of-bound access when `IS_NON_WS(s[n])`. Version 1.13.8 contains a patch for this issue.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade sofia-sip | Aug 22, 2024 | May 31, 2022 |
| Debian | — | Upgrade sofia-sip | Sep 6, 2022 | May 31, 2022 |
| Gentoo Linux | — | Upgrade net-libs/sofia-sip. | Oct 31, 2022 | May 31, 2022 |
| Ubuntu | — | Upgrade sofia-sip-bin (Ubuntu Pro)Upgrade sofia-sip-binUpgrade libsofia-sip-ua0Upgrade libsofia-sip-ua-glib3 (Ubuntu Pro)Upgrade libsofia-sip-ua0 (Ubuntu Pro)Upgrade libsofia-sip-ua-glib3 | Mar 22, 2023 | May 31, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub