Описание
Security update for libosip2
This update for libosip2 fixes several issues.
These security issues were fixed:
- CVE-2017-7853: In libosip2 a malformed SIP message could have lead to a heap buffer overflow in the msg_osip_body_parse() function defined in osipparser2/osip_message_parse.c, resulting in a remote DoS (bsc#1034570)
- CVE-2016-10326: In libosip2 a malformed SIP message could have lead to a heap buffer overflow in the osip_body_to_str() function defined in osipparser2/osip_body.c, resulting in a remote DoS (bsc#1034571)
- CVE-2016-10325: In libosip2 a malformed SIP message could have lead to a heap buffer overflow in the _osip_message_to_str() function defined in osipparser2/osip_message_to_str.c, resulting in a remote DoS (bsc#1034572)
- CVE-2016-10324: In libosip2 a malformed SIP message could have lead to a heap buffer overflow in the osip_clrncpy() function defined in osipparser2/osip_port.c (bsc#1034574)
Список пакетов
SUSE Linux Enterprise Software Development Kit 11 SP4
Ссылки
- Link for SUSE-SU-2017:1188-1
- E-Mail link for SUSE-SU-2017:1188-1
- SUSE Security Ratings
- SUSE Bug 1034570
- SUSE Bug 1034571
- SUSE Bug 1034572
- SUSE Bug 1034574
- SUSE CVE CVE-2016-10324 page
- SUSE CVE CVE-2016-10325 page
- SUSE CVE CVE-2016-10326 page
- SUSE CVE CVE-2017-7853 page
Описание
In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_clrncpy() function defined in osipparser2/osip_port.c.
Затронутые продукты
Ссылки
- CVE-2016-10324
- SUSE Bug 1034574
Описание
In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the _osip_message_to_str() function defined in osipparser2/osip_message_to_str.c, resulting in a remote DoS.
Затронутые продукты
Ссылки
- CVE-2016-10325
- SUSE Bug 1034572
Описание
In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_body_to_str() function defined in osipparser2/osip_body.c, resulting in a remote DoS.
Затронутые продукты
Ссылки
- CVE-2016-10326
- SUSE Bug 1034571
Описание
In libosip2 in GNU oSIP 4.1.0 and 5.0.0, a malformed SIP message can lead to a heap buffer overflow in the msg_osip_body_parse() function defined in osipparser2/osip_message_parse.c, resulting in a remote DoS.
Затронутые продукты
Ссылки
- CVE-2017-7853
- SUSE Bug 1034570