First published: Mon Oct 18 2021(Updated: )
An issue was discovered in function sofia_handle_sip_i_notify in sofia.c in SignalWire freeswitch before 1.10.6, may allow attackers to view sensitive information due to an uninitialized value.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SignalWire freeswitch | <1.10.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-36513 is a vulnerability in SignalWire freeswitch that may allow attackers to view sensitive information due to an uninitialized value.
The severity of CVE-2021-36513 is high with a CVSS score of 7.5.
CVE-2021-36513 affects SignalWire freeswitch versions up to and excluding 1.10.6.
To fix CVE-2021-36513, upgrade to SignalWire freeswitch version 1.10.6 or later.
You can find more information about CVE-2021-36513 on the following references: [GitHub Issue](https://github.com/signalwire/freeswitch/issues/1245), [GitHub Release](https://github.com/signalwire/freeswitch/releases/tag/v1.10.6), [Newreleases.io](https://newreleases.io/project/github/signalwire/freeswitch/release/v1.10.6).