USN-6448-1: Sofia-SIP vulnerability
24 October 2023
Sofia-SIP could be made to crash or run programs if it received specially crafted network traffic.
Releases
Packages
- sofia-sip - Sofia-SIP library development files
Details
Xu Biang discovered that Sofia-SIP did not properly manage memory when
handling STUN packets. An attacker could use this issue to cause
Sofia-SIP to crash, resulting in a denial of service, or possibly execute
arbitrary code.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 23.10
-
libsofia-sip-ua-glib3
-
1.12.11+20110422.1+1e14eea~dfsg-4ubuntu1.23.10.1
-
libsofia-sip-ua0
-
1.12.11+20110422.1+1e14eea~dfsg-4ubuntu1.23.10.1
-
sofia-sip-bin
-
1.12.11+20110422.1+1e14eea~dfsg-4ubuntu1.23.10.1
Ubuntu 23.04
-
libsofia-sip-ua-glib3
-
1.12.11+20110422.1+1e14eea~dfsg-4ubuntu1.23.04.1
-
libsofia-sip-ua0
-
1.12.11+20110422.1+1e14eea~dfsg-4ubuntu1.23.04.1
-
sofia-sip-bin
-
1.12.11+20110422.1+1e14eea~dfsg-4ubuntu1.23.04.1
Ubuntu 22.04
-
libsofia-sip-ua-glib3
-
1.12.11+20110422.1-2.1+deb10u3ubuntu0.22.04.2
-
libsofia-sip-ua0
-
1.12.11+20110422.1-2.1+deb10u3ubuntu0.22.04.2
-
sofia-sip-bin
-
1.12.11+20110422.1-2.1+deb10u3ubuntu0.22.04.2
Ubuntu 20.04
-
libsofia-sip-ua-glib3
-
1.12.11+20110422.1-2.1+deb10u3ubuntu0.20.04.2
-
libsofia-sip-ua0
-
1.12.11+20110422.1-2.1+deb10u3ubuntu0.20.04.2
-
sofia-sip-bin
-
1.12.11+20110422.1-2.1+deb10u3ubuntu0.20.04.2
Ubuntu 18.04
-
libsofia-sip-ua-glib3
-
1.12.11+20110422.1-2.1+deb10u3ubuntu0.18.04.1~esm1
Available with Ubuntu Pro
-
libsofia-sip-ua0
-
1.12.11+20110422.1-2.1+deb10u3ubuntu0.18.04.1~esm1
Available with Ubuntu Pro
-
sofia-sip-bin
-
1.12.11+20110422.1-2.1+deb10u3ubuntu0.18.04.1~esm1
Available with Ubuntu Pro
Ubuntu 16.04
-
libsofia-sip-ua-glib3
-
1.12.11+20110422.1-2.1+deb10u3ubuntu0.16.04.1~esm2
Available with Ubuntu Pro
-
libsofia-sip-ua0
-
1.12.11+20110422.1-2.1+deb10u3ubuntu0.16.04.1~esm2
Available with Ubuntu Pro
-
sofia-sip-bin
-
1.12.11+20110422.1-2.1+deb10u3ubuntu0.16.04.1~esm2
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.