An issue was discovered in the libsofia-sip fork in drachtio-server before 0.8.20. It allows remote attackers to cause a denial of service (daemon crash) via a crafted UDP message that leads to a failure of the libsofia-sip-ua/tport/tport.c self assertion.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade sofia-sip | Feb 24, 2023 | Dec 18, 2022 |
| Ubuntu | — | Upgrade libsofia-sip-ua0 (Ubuntu Pro)Upgrade libsofia-sip-ua-glib3Upgrade sofia-sip-binUpgrade sofia-sip-bin (Ubuntu Pro)Upgrade libsofia-sip-ua0Upgrade libsofia-sip-ua-glib3 (Ubuntu Pro) | Mar 22, 2023 | Dec 18, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub