Multiple vulnerabilities have been found in PJSIP, the worst of which could result in a Denial of Service condition.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202107-42 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Low Title: PJSIP: Multiple vulnerabilities Date: July 20, 2021 Bugs: #775359 ID: 202107-42 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in PJSIP, the worst of which could result in a Denial of Service condition. Background ========= PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-libs/pjproject < 2.10-r1 > = 2.10-r1 Description ========== Multiple vulnerabilities have been discovered in PJSIP. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All PJSIP users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-libs/pjproject-2.10-r1" References ========= [ 1 ] CVE-2020-15260 https://nvd.nist.gov/vuln/detail/CVE-2020-15260 [ 2 ] CVE-2021-21375 https://nvd.nist.gov/vuln/detail/CVE-2021-21375 Availability =========== This GLSA and any updates to it are available for viewing at the GentooSecurity Website: https://security.gentoo.org/glsa/202107-42 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
- Update to upstream 3.5.13 release. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-f646217583 2017-06-11 16:12:43.870858 --------------------------------------------------------------------------------Name : gnutls Product : Fedora 25 Version : 3.5.13 Release : 1.fc25 URL : http://www.gnutls.org/ Summary : A TLS protocol implementation Description : GnuTLS is a secure communications library implementing the SSL, TLS and DTLS protocols and technologies around them. It provides a simple C language application programming interface (API) to access the secure communications protocols as well as APIs to parse and write X.509, PKCS #12, OpenPGP and other required structures. --------------------------------------------------------------------------------Update Information: - Update to upstream 3.5.13 release --------------------------------------------------------------------------------References: [ 1 ] Bug #1454411 https://bugzilla.redhat.com/show_bug.cgi?id=1454411 [ 2 ] Bug #1459795 - CVE-2017-7507 gnutls: Crash upon receiving well-formed status_request extension [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1459795 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade gnutls' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.