USN-6448-1: Sofia-SIP vulnerability
Xu Biang discovered that Sofia-SIP did not properly manage memory when handling STUN packets. An attacker could use this issue to cause Sofia-SIP to crash, resulting in a denial of service, or possibly execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for the Sofia-SIP vulnerability?
The vulnerability ID for the Sofia-SIP vulnerability is USN-6448-1.
What is the impact of the Sofia-SIP vulnerability?
The Sofia-SIP vulnerability can result in a denial of service or allow an attacker to execute arbitrary code.
How does an attacker exploit the Sofia-SIP vulnerability?
An attacker can exploit the Sofia-SIP vulnerability by sending specially crafted STUN packets.
Which versions of Ubuntu are affected by the Sofia-SIP vulnerability?
The Sofia-SIP vulnerability affects Ubuntu versions 23.10, 23.04, 22.04, 20.04, 18.04, and 16.04.
How can I fix the Sofia-SIP vulnerability?
To fix the Sofia-SIP vulnerability, update to version 1.12.11+20110422.1+1e14eea~dfsg-4ubuntu1.23.10.1 for Ubuntu 23.10, or the respective updated versions for other affected Ubuntu versions.