Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Debian 10 Buster DLA-3549-1: Serious Risks from Critical Ring DoS

debian lts
Calendar Grey August 29, 2023
Dist Debian Esm H88
Concerns identified within the Ring system regarding insufficient boundary validation, resulting in possible service disruption and various significant threats.
Several issue have been found in ring/jami, a secure and distributed voice, video and chat platform

Summary

Several issue have been found in ring/jami, a secure and distributed
voice, video and chat platform.
The issues are about missing boundary checks, resulting in out-of-bound
read access, buffer overflow or denial-of-service.


For Debian 10 buster, these problems have been fixed in version
20190215.1.f152c98~ds1-1+deb10u2.

We recommend that you upgrade your ring/jami packages.

For the detailed security status of ring please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/ring

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



Severity
critical
Lowest
Low
Medium
High
Critical

Package: ring
Version: 20190215.1.f152c98~ds1-1+deb10u2
CVE ID: CVE-2021-37706 CVE-2021-43299 CVE-2021-43300

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here