Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Fedora 40 Advisory: FEDORA-2024-a63e807450 Critical: Baresip DoS

fedora
Calendar Grey March 23, 2024
Dist Fedora Esm H88
Fedora's latest update has released version 3.10.1 of baresip to address a Denial of Service vulnerability, enhancing system security and resilience.
Baresip v3.10.1 (2024-03-12) Security Release (possible Denial of Service): A wrong or manipulated incoming RTP Timestamp can cause the baresip process to hang forever, for details...

Summary

Libre is a generic library for real-time communications with async I/O

support. Features are a SIP stack (RFC 3261), SDP, RTP and RTCP, SRTP and

SRTCP (Secure RTP), DNS client, STUN/TURN/ICE stack, BFCP, HTTP stack with

client/server, Websockets, Jitter buffer, async I/O (poll, epoll, select,

kqueue), UDP/TCP/TLS/DTLS transport, JSON parser and Real Time Messaging

Protocol (RTMP).

Update Information:

Baresip v3.10.1 (2024-03-12) Security Release (possible Denial of Service): A wrong or manipulated incoming RTP Timestamp can cause the baresip process to hang forever, for details see: #2954 aureceiver: fix mtx_unlock on discard Baresip v3.10.0 (2024-03-06) cmake: use default value for CMAKE_C_EXTENSIONS cmake: add /usr/{local,}/include/re and /usr/{local,}/lib{64,} to FindRE.cmake test/main: fix NULL pointer arg on err ci: add Fedora workflow to avoid e.g. rpath issues mediatrack/start: add audio_decoder_set config: support distribution-specific/default CA paths readme: cosmetic changes ci/fedora: fix dependency config: add default CA path for Android transp,tls: add TLS client verification account,message,ua: secure incoming SIP MESSAGEs aufile: avoid race condition in case of fast destruction aufile: join thread if write fails video: add video_req_keyframe api call: start streams in sipsess_estab_handler webrtc: add av1 codec cmake: fix relative source dir ...

Change Log

* Sun Mar 10 2024 Robert Scheck 3.10.0-1 - Upgrade to 3.10.0 (#2268236)

References


[ 1 ] Bug #2268236 - libre-3.10.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2268236 [ 2 ] Bug #2268424 - baresip-3.10.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2268424 [ 3 ] Bug #2269261 - baresip-3.10.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2269261

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-a63e807450' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: libre
Product: Fedora 40
Version: 3.10.0
Release: 1.fc40
Summary: Generic library for real-time communications

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here