Mageia 2023-0040: sofia-sip security update
Summary
Missing message length and attributes length checks** when it handles STUN
packets, leading to controllable heap-over-flow (CVE-2023-22741)
References
- https://bugs.mageia.org/show_bug.cgi?id=31493
- https://www.debian.org/lts/security/2023/dla-3292
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22741
Resolution
MGASA-2023-0040 - Updated sofia-sip packages fix security vulnerability
SRPMS
- 8/core/sofia-sip-1.12.11-10.2.mga8