First published: Tue Oct 24 2023(Updated: )
Xu Biang discovered that Sofia-SIP did not properly manage memory when handling STUN packets. An attacker could use this issue to cause Sofia-SIP to crash, resulting in a denial of service, or possibly execute arbitrary code.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libsofia-sip-ua-glib3 | <1.12.11+20110422.1+1e14eea~dfsg-4ubuntu1.23.10.1 | 1.12.11+20110422.1+1e14eea~dfsg-4ubuntu1.23.10.1 |
Ubuntu Linux | =23.10 | |
All of | ||
ubuntu/libsofia-sip-ua0 | <1.12.11+20110422.1+1e14eea~dfsg-4ubuntu1.23.10.1 | 1.12.11+20110422.1+1e14eea~dfsg-4ubuntu1.23.10.1 |
Ubuntu Linux | =23.10 | |
All of | ||
ubuntu/sofia-sip-bin | <1.12.11+20110422.1+1e14eea~dfsg-4ubuntu1.23.10.1 | 1.12.11+20110422.1+1e14eea~dfsg-4ubuntu1.23.10.1 |
Ubuntu Linux | =23.10 | |
All of | ||
ubuntu/libsofia-sip-ua-glib3 | <1.12.11+20110422.1+1e14eea~dfsg-4ubuntu1.23.04.1 | 1.12.11+20110422.1+1e14eea~dfsg-4ubuntu1.23.04.1 |
Ubuntu Linux | =23.04 | |
All of | ||
ubuntu/libsofia-sip-ua0 | <1.12.11+20110422.1+1e14eea~dfsg-4ubuntu1.23.04.1 | 1.12.11+20110422.1+1e14eea~dfsg-4ubuntu1.23.04.1 |
Ubuntu Linux | =23.04 | |
All of | ||
ubuntu/sofia-sip-bin | <1.12.11+20110422.1+1e14eea~dfsg-4ubuntu1.23.04.1 | 1.12.11+20110422.1+1e14eea~dfsg-4ubuntu1.23.04.1 |
Ubuntu Linux | =23.04 | |
All of | ||
ubuntu/libsofia-sip-ua-glib3 | <1.12.11+20110422.1-2.1+deb10u3ubuntu0.22.04.2 | 1.12.11+20110422.1-2.1+deb10u3ubuntu0.22.04.2 |
Ubuntu Linux | =22.04 | |
All of | ||
ubuntu/libsofia-sip-ua0 | <1.12.11+20110422.1-2.1+deb10u3ubuntu0.22.04.2 | 1.12.11+20110422.1-2.1+deb10u3ubuntu0.22.04.2 |
Ubuntu Linux | =22.04 | |
All of | ||
ubuntu/sofia-sip-bin | <1.12.11+20110422.1-2.1+deb10u3ubuntu0.22.04.2 | 1.12.11+20110422.1-2.1+deb10u3ubuntu0.22.04.2 |
Ubuntu Linux | =22.04 | |
All of | ||
ubuntu/libsofia-sip-ua-glib3 | <1.12.11+20110422.1-2.1+deb10u3ubuntu0.20.04.2 | 1.12.11+20110422.1-2.1+deb10u3ubuntu0.20.04.2 |
Ubuntu Linux | =20.04 | |
All of | ||
ubuntu/libsofia-sip-ua0 | <1.12.11+20110422.1-2.1+deb10u3ubuntu0.20.04.2 | 1.12.11+20110422.1-2.1+deb10u3ubuntu0.20.04.2 |
Ubuntu Linux | =20.04 | |
All of | ||
ubuntu/sofia-sip-bin | <1.12.11+20110422.1-2.1+deb10u3ubuntu0.20.04.2 | 1.12.11+20110422.1-2.1+deb10u3ubuntu0.20.04.2 |
Ubuntu Linux | =20.04 | |
All of | ||
ubuntu/libsofia-sip-ua-glib3 | <1.12.11+20110422.1-2.1+deb10u3ubuntu0.18.04.1~esm1 | 1.12.11+20110422.1-2.1+deb10u3ubuntu0.18.04.1~esm1 |
Ubuntu Linux | =18.04 | |
All of | ||
ubuntu/libsofia-sip-ua0 | <1.12.11+20110422.1-2.1+deb10u3ubuntu0.18.04.1~esm1 | 1.12.11+20110422.1-2.1+deb10u3ubuntu0.18.04.1~esm1 |
Ubuntu Linux | =18.04 | |
All of | ||
ubuntu/sofia-sip-bin | <1.12.11+20110422.1-2.1+deb10u3ubuntu0.18.04.1~esm1 | 1.12.11+20110422.1-2.1+deb10u3ubuntu0.18.04.1~esm1 |
Ubuntu Linux | =18.04 | |
All of | ||
ubuntu/libsofia-sip-ua-glib3 | <1.12.11+20110422.1-2.1+deb10u3ubuntu0.16.04.1~esm2 | 1.12.11+20110422.1-2.1+deb10u3ubuntu0.16.04.1~esm2 |
Ubuntu Linux | =16.04 | |
All of | ||
ubuntu/libsofia-sip-ua0 | <1.12.11+20110422.1-2.1+deb10u3ubuntu0.16.04.1~esm2 | 1.12.11+20110422.1-2.1+deb10u3ubuntu0.16.04.1~esm2 |
Ubuntu Linux | =16.04 | |
All of | ||
ubuntu/sofia-sip-bin | <1.12.11+20110422.1-2.1+deb10u3ubuntu0.16.04.1~esm2 | 1.12.11+20110422.1-2.1+deb10u3ubuntu0.16.04.1~esm2 |
Ubuntu Linux | =16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the Sofia-SIP vulnerability is USN-6448-1.
The Sofia-SIP vulnerability can result in a denial of service or allow an attacker to execute arbitrary code.
An attacker can exploit the Sofia-SIP vulnerability by sending specially crafted STUN packets.
The Sofia-SIP vulnerability affects Ubuntu versions 23.10, 23.04, 22.04, 20.04, 18.04, and 16.04.
To fix the Sofia-SIP vulnerability, update to version 1.12.11+20110422.1+1e14eea~dfsg-4ubuntu1.23.10.1 for Ubuntu 23.10, or the respective updated versions for other affected Ubuntu versions.