CVE-2021-43610: High severity linphone vulnerability
Published Nov 12, 2021
·Updated
Belledonne Belle-sip before 5.0.20 can crash applications such as Linphone via an invalid From header (request URI without a parameter) in an unauthenticated SIP message, a different issue than CVE-2021-33056.
Affected Software
1 affected component
Linphone Belle-sip<5.0.20
Remediation
Event History
Nov 12, 2021
CVE Published
via MITRE·09:53 PM
Data Sourced
via MITRE·09:53 PM
Description
Data Sourced
via NVD·10:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-43610?
CVE-2021-43610 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2021-43610?
To fix CVE-2021-43610, upgrade to Belle-sip version 5.0.20 or later.
3
What type of applications are affected by CVE-2021-43610?
Applications such as Linphone that use Belle-sip versions before 5.0.20 are affected.
4
What specifically causes the vulnerability in CVE-2021-43610?
CVE-2021-43610 is caused by an invalid From header in an unauthenticated SIP message.
5
What impact does CVE-2021-43610 have on affected applications?
CVE-2021-43610 can cause crashes in applications like Linphone due to the vulnerability.