Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Mageia 8: MGASA-2021-0559 Moderate: PJProject Denial Of Service Risk

mageia
Calendar Grey December 19, 2021
Dist Mageia Esm H88
Mageia has released MGASA-2021-0560 which tackles vulnerabilities in OpenSSL potentially exposing users to data breaches.
Updated pjproject packages fix security vulnerability: In PJSIP before version 2.11.1, there are a couple of issues found in the SSL socket

Summary

Updated pjproject packages fix security vulnerability:
In PJSIP before version 2.11.1, there are a couple of issues found in the SSL socket. First, a race condition between callback and destroy, due to the accepted socket having no group lock. Second, the SSL socket parent/ listener may get destroyed during handshake. Both issues were reported to happen intermittently in heavy load TLS connections. They cause a crash, resulting in a denial of service (CVE-2021-32686).

References

- https://bugs.mageia.org/show_bug.cgi?id=29317

- https://www.cve.org/CVERecord?id=CVE-2021-32686

Resolution

SRPMS

- 8/core/pjproject-2.10-5.3.mga8

Publication date: 19 Dec 2021
URL: https://advisories.mageia.org/MGASA-2021-0559.html
Type: security
CVE: CVE-2021-32686

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here