Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Fedora 40: Advisory on Baresip 3.10.1 Denial of Service Vulnerability

fedora
Calendar Grey March 23, 2024
Dist Fedora Esm H88
Baresip security patch tackles DoS vulnerabilities caused by altered RTP timestamps in the Fedora 40 update.
Baresip v3.10.1 (2024-03-12) Security Release (possible Denial of Service): A wrong or manipulated incoming RTP Timestamp can cause the baresip process to hang forever, for details...

Summary

A modular SIP user-agent with support for audio and video, and many IETF

standards such as SIP, SDP, RTP/RTCP and STUN/TURN/ICE for both, IPv4 and

IPv6.

Additional modules provide support for audio codecs like Codec2, G.711,

G.722, G.726, GSM, L16, MPA and Opus, audio drivers like ALSA, GStreamer,

JACK Audio Connection Kit, Portaudio, and PulseAudio, video codecs like

AV1, VP8 or VP9, video sources like Video4Linux, video outputs like SDL2

or X11, NAT traversal via STUN, TURN, ICE, and NAT-PMP, media encryption

via TLS, SRTP or DTLS-SRTP, management features like embedded web-server

with HTTP interface, command-line console and interface, and MQTT.

Update Information:

Baresip v3.10.1 (2024-03-12) Security Release (possible Denial of Service): A wrong or manipulated incoming RTP Timestamp can cause the baresip process to hang forever, for details see: #2954 aureceiver: fix mtx_unlock on discard Baresip v3.10.0 (2024-03-06) cmake: use default value for CMAKE_C_EXTENSIONS cmake: add /usr/{local,}/include/re and /usr/{local,}/lib{64,} to FindRE.cmake test/main: fix NULL pointer arg on err ci: add Fedora workflow to avoid e.g. rpath issues mediatrack/start: add audio_decoder_set config: support distribution-specific/default CA paths readme: cosmetic changes ci/fedora: fix dependency config: add default CA path for Android transp,tls: add TLS client verification account,message,ua: secure incoming SIP MESSAGEs aufile: avoid race condition in case of fast destruction aufile: join thread if write fails video: add video_req_keyframe api call: start streams in sipsess_estab_handler webrtc: add av1 codec cmake: fix relative source dir ...

Change Log

* Tue Mar 12 2024 Robert Scheck 3.10.1-1 - Upgrade to 3.10.1 (#2269261) * Mon Mar 11 2024 Robert Scheck 3.10.0-2 - Added upstream patch to fix mtx_unlock on discard in aureceiver * Sun Mar 10 2024 Robert Scheck 3.10.0-1 - Upgrade to 3.10.0 (#2268424)

References


[ 1 ] Bug #2268236 - libre-3.10.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2268236 [ 2 ] Bug #2268424 - baresip-3.10.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2268424 [ 3 ] Bug #2269261 - baresip-3.10.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2269261

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-a63e807450' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
important
Lowest
Low
Medium
High
Critical

Name: baresip
Product: Fedora 40
Version: 3.10.1
Release: 1.fc40
Summary: Modular SIP user-agent with audio and video support

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here