An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for libosip2 ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:3724-1 Rating: important References: #1204225 Cross-References: CVE-2022-41550 CVSS scores: CVE-2022-41550 (NVD) : 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2022-41550 (SUSE): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: SUSE Linux Enterprise Desktop 12-SP5 SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server for SAP Applications 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Workstation Extension 12-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libosip2 fixes the following issues: - CVE-2022-41550: Fixed an integer overflow in osip_body_parse_header (bsc#1204225). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 12-SP5: zypper in -t patch SUSE-SLE-WE-12-SP5-2022-3724=1 - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2022-3724=1 Package List: - SUSE Linux Enterprise Workstation Extension 12-SP5 (x86_64): libosip2-3.5.0-21.3.1 libosip2-debuginfo-3.5.0-21.3.1 libosip2-debugsource-3.5.0-21.3.1 - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): libosip2-3.5.0-21.3.1 libosip2-debuginfo-3.5.0-21.3.1 libosip2-debugsource-3.5.0-21.3.1 libosip2-devel-3.5.0-21.3.1 References: https://www.suse.com/security/cve/CVE-2022-41550.html https://bugzilla.suse.com/1204225 . SUSE has released a security update for libosip2 addressing an integer overflow vulnerability, categorized with a high importance rating.. libosip2 Update,SUSE Security Advisory,Important Fix. . Severity: Important. LinuxSecurity.com Team
GNU oSIP v5.3.0 was discovered to contain an integer overflow via the component osip_body_parse_header. (CVE-2022-41550) References: - https://bugs.mageia.org/show_bug.cgi?id=30963 . MGASA-2022-0389 - Updated libosip2 packages fix security vulnerability Publication date: 23 Oct 2022 URL: https://advisories.mageia.org/MGASA-2022-0389.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-41550 GNU oSIP v5.3.0 was discovered to contain an integer overflow via the component osip_body_parse_header. (CVE-2022-41550) References: - https://bugs.mageia.org/show_bug.cgi?id=30963 - - https://www.cve.org/CVERecord?id=CVE-2022-41550 SRPMS: - 8/core/libosip2-5.0.0-4.1.mga8 . The security patch MGASA-2022-0389 for libosip2 tackles an integer overflow flaw found in GNU oSIP.. Mageia, Libosip2, Integer Overflow, Security Update, MGASA-2022-0389. . Severity: Critical. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for libosip2 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2022:10147-1 Rating: important References: #1204225 Cross-References: CVE-2022-41550 CVSS scores: CVE-2022-41550 (SUSE): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: openSUSE Backports SLE-15-SP4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libosip2 fixes the following issues: - CVE-2022-41550: Fixed an integer overflow in the header parser (boo#1204225) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP4: zypper in -t patch openSUSE-2022-10147=1 Package List: - openSUSE Backports SLE-15-SP4 (aarch64 i586 ppc64le s390x x86_64): libosip2-12-5.2.1-bp154.2.3.1 libosip2-devel-5.2.1-bp154.2.3.1 References: https://www.suse.com/security/cve/CVE-2022-41550.html https://bugzilla.suse.com/1204225 . An update for openSUSE addressing a critical integer overflow vulnerability in libosip2 is now available. Please install the most recent patch immediately.. openSUSE Security Updates, Libosip2 Integer Overflow, Important Security Patch. . Severity: Important. LinuxSecurity.com Team
Multiple security vulnerabilities have been found in oSIP, a library implementing the Session Initiation Protocol, which might result in denial of service through malformed SIP messages. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3879-1
An update that fixes four vulnerabilities is now available. An update that fixes four vulnerabilities is now available. An update that fixes four vulnerabilities is now available.. openSUSE Security Update: Security update for libosip2 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2017:1127-1 Rating: important References: #1034570 #1034571 #1034572 #1034574 Cross-References: CVE-2016-10324 CVE-2016-10325 CVE-2016-10326 CVE-2017-7853 Affected Products: openSUSE Leap 42.2 openSUSE Leap 42.1 ______________________________________________________________________________ An update that fixes four vulnerabilities is now available. Description: This update for libosip2 fixes the following issues: Changes in libosip2: - CVE-2017-7853: In libosip2 in GNU 5.0.0, a malformed SIP message can lead to a heap buffer overflow in the msg_osip_body_parse() function defined in osipparser2/osip_message_parse.c, resulting in a remote DoS. (boo#1034570) - CVE-2016-10326: In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_body_to_str() function defined in osipparser2/osip_body.c, resulting in a remote DoS. (boo#1034571) - CVE-2016-10325: In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the _osip_message_to_str() function defined in osipparser2/osip_message_to_str.c, resulting in a remote DoS. (boo#1034572) - CVE-2016-10324: In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_clrncpy() function defined in osipparser2/osip_port.c. (boo#1034574) Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE Leap 42.2: zypper in -t patchopenSUSE-2017-526=1 - openSUSE Leap 42.1: zypper in -t patch openSUSE-2017-526=1 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE Leap 42.2 (x86_64): libosip2-4.1.0-5.3.1 libosip2-debuginfo-4.1.0-5.3.1 libosip2-debugsource-4.1.0-5.3.1 libosip2-devel-4.1.0-5.3.1 - openSUSE Leap 42.1 (i586 x86_64): libosip2-4.1.0-5.1 libosip2-debuginfo-4.1.0-5.1 libosip2-debugsource-4.1.0-5.1 libosip2-devel-4.1.0-5.1 References: https://www.suse.com/security/cve/CVE-2016-10324.html https://www.suse.com/security/cve/CVE-2016-10325.html https://www.suse.com/security/cve/CVE-2016-10326.html https://www.suse.com/security/cve/CVE-2017-7853.html https://bugzilla.suse.com/1034570 https://bugzilla.suse.com/1034571 https://bugzilla.suse.com/1034572 https://bugzilla.suse.com/1034574 . Important patch for Fedora fixes severe vulnerabilities in libosip2, improving overall system reliability and security.. openSUSE Update, libosip2 Patch, Security Fixes, Critical Update. . Severity: Important. LinuxSecurity.com Team
CVE-2016-10324 In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_clrncpy() function defined in . Hash: SHA512 Package : libosip2 Version : 3.6.0-4+deb7u1 CVE ID : CVE-2016-10324 CVE-2016-10325 CVE-2016-10326 CVE-2017-7853 CVE-2016-10324 In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_clrncpy() function defined in osipparser2/osip_port.c. CVE-2016-10325 In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the _osip_message_to_str() function defined in osipparser2/osip_message_to_str.c, resulting in a remote DoS. CVE-2016-10326 In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_body_to_str() function defined in osipparser2/osip_body.c, resulting in a remote DoS. CVE-2017-7853 In libosip2 in GNU oSIP 5.0.0, a malformed SIP message can lead to a heap buffer overflow in the msg_osip_body_parse() function defined in osipparser2/osip_message_parse.c, resulting in a remote DoS. For Debian 7 "Wheezy", these problems have been fixed in version 3.6.0-4+deb7u1. We recommend that you upgrade your libosip2 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance libosip2 to address heap buffer overflow vulnerabilities in Debian 7 stemming from improperly formatted SIP communications. Urgent security patch required.. Debian Security, libosip2 Update, DoS Threats, Buffer Overflow Exploit. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.