Updated pjproject packages fix security vulnerability:
In PJSIP before version 2.11.1, there are a couple of issues found in the
SSL socket. First, a race condition between callback and destroy, due to
the accepted socket having no group lock. Second, the SSL socket parent/
listener may get destroyed during handshake. Both issues were reported to
happen intermittently in heavy load TLS connections. They cause a crash,
resulting in a denial of service (CVE-2021-32686).
- https://bugs.mageia.org/show_bug.cgi?id=29317
- https://www.cve.org/CVERecord?id=CVE-2021-32686
- 8/core/pjproject-2.10-5.3.mga8
Get the latest Linux and open source security news straight to your inbox.