https://seclists.org/oss-sec/2023/q4/328: [ES2023-02] FreeSWITCH susceptible to Denial of Service via DTLS Hello packets during call initiation
Published Dec 23, 2023
·Updated
Affected Software
1 affected component
SignalWire freeswitch
Frequently Asked Questions
1
What is the severity of ES2023-02?
The severity of ES2023-02 is classified as a Denial of Service vulnerability that affects FreeSWITCH.
2
How do I fix ES2023-02?
To fix ES2023-02, upgrade to FreeSWITCH version 1.10.11 or later.
3
What type of attack does ES2023-02 facilitate?
ES2023-02 facilitates Denial of Service attacks through the exploitation of DTLS Hello packets during call initiation.
4
Which software is affected by ES2023-02?
FreeSWITCH, particularly the versions prior to 1.10.11, is affected by ES2023-02.
5
When was ES2023-02 published?
ES2023-02 was published on December 23, 2023.