Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.1.10.2022.0343
Kategorie:Mageia Linux Local Security Checks
Titel:Mageia: Security Advisory (MGASA-2022-0343)
Zusammenfassung:The remote host is missing an update for the 'sofia-sip' package(s) announced via the MGASA-2022-0343 advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'sofia-sip' package(s) announced via the MGASA-2022-0343 advisory.

Vulnerability Insight:
An attacker can send a message with evil sdp to FreeSWITCH, which may
a cause a crash due to an out-of-bounds access. (CVE-2022-31001)
An attacker can send a message with evil sdp to FreeSWITCH, which may
cause a crash. (CVE-2022-31002)
An out-of-bounds write. (CVE-2022-31003)

Affected Software/OS:
'sofia-sip' package(s) on Mageia 8.

Solution:
Please install the updated package(s).

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2022-31001
https://github.com/freeswitch/sofia-sip/security/advisories/GHSA-79jq-hh82-cv9g
Debian Security Information: DSA-5410 (Google Search)
https://www.debian.org/security/2023/dsa-5410
https://security.gentoo.org/glsa/202210-18
https://github.com/freeswitch/sofia-sip/commit/a99804b336d0e16d26ab7119d56184d2d7110a36
https://lists.debian.org/debian-lts-announce/2022/09/msg00001.html
Common Vulnerability Exposure (CVE) ID: CVE-2022-31002
https://github.com/freeswitch/sofia-sip/security/advisories/GHSA-g3x6-p824-x6hm
https://github.com/freeswitch/sofia-sip/commit/51841eb53679434a386fb2dcbca925dcc48d58ba
Common Vulnerability Exposure (CVE) ID: CVE-2022-31003
https://github.com/freeswitch/sofia-sip/security/advisories/GHSA-8w5j-6g2j-pxcp
https://github.com/freeswitch/sofia-sip/commit/907f2ac0ee504c93ebfefd676b4632a3575908c9
CopyrightCopyright (C) 2022 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.