Your message dated Mon, 14 Sep 2026 10:05:02 +0000
with message-id <[email protected]>
and subject line Bug#1147622: fixed in sngrep 1.8.4-2
has caused the Debian Bug report #1147622,
regarding sngrep: CVE-2026-90558
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1147622: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1147622
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: sngrep
X-Debbugs-CC: [email protected]
Severity: important
Tags: security

Hi,

The following vulnerability was published for sngrep.

CVE-2026-90558[0]:
| sngrep through 1.8.4 contains stack buffer overflow vulnerabilities
| in SIP attribute formatting routines when header values exceed the
| 255-byte buffer limit. Attackers can craft malicious SIP packets
| with oversized Call-ID, X-Call-ID, or other header fields to
| overflow stack buffers and cause crashes or execute arbitrary code
| during packet parsing and rendering.

Fixed by: 
https://github.com/irontec/sngrep/commit/1ff74ee3ab5ff280e8ba976aa8c744dca57eb35b

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-90558
    https://www.cve.org/CVERecord?id=CVE-2026-90558

Please adjust the affected versions in the BTS as needed.

--- End Message ---
--- Begin Message ---
Source: sngrep
Source-Version: 1.8.4-2
Done: Victor Seva <[email protected]>

We believe that the bug you reported is fixed in the latest version of
sngrep, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Victor Seva <[email protected]> (supplier of updated sngrep package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Mon, 14 Sep 2026 11:29:10 +0200
Source: sngrep
Architecture: source
Version: 1.8.4-2
Distribution: unstable
Urgency: high
Maintainer: Debian VoIP Team <[email protected]>
Changed-By: Victor Seva <[email protected]>
Closes: 1147622
Changes:
 sngrep (1.8.4-2) unstable; urgency=high
 .
   * CVE-2026-90558 fix from upstream (Closes: #1147622)
Checksums-Sha1:
 55740af957088868a938c91949e6ede2255e5e8d 1668 sngrep_1.8.4-2.dsc
 ddae09760cdba71166ed7c31fa378f4b06b940e7 6244 sngrep_1.8.4-2.debian.tar.xz
 57587c43b3b68ee5e231a88c5503b6a01439b0e2 6284 sngrep_1.8.4-2_amd64.buildinfo
Checksums-Sha256:
 3080d5b360c8c7990ef7745a91c56e7f015cc71ea3d4a399a3e6d66c8b85b578 1668 
sngrep_1.8.4-2.dsc
 2698b2f512c0a9b655d6a0dc3fa3041d3580f44d2b385796f76e18884f35adfa 6244 
sngrep_1.8.4-2.debian.tar.xz
 65f23570415f2d1c551dfd591e1a3344f15e77c07976c52ea961eab69ea5fda8 6284 
sngrep_1.8.4-2_amd64.buildinfo
Files:
 0ab3841f7eaaa608a8cac9ef985ab74f 1668 comm optional sngrep_1.8.4-2.dsc
 1f1063997ef976514f7545a6228bf538 6244 comm optional 
sngrep_1.8.4-2.debian.tar.xz
 ef22067e06c1cc3cf881c283d5e3e66a 6284 comm optional 
sngrep_1.8.4-2_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iIcEARYKAC8WIQQq6AO8RS0zF4SC1vh9e2XEKg7IsgUCaqfAqREcdnNldmFAZGVi
aWFuLm9yZwAKCRB9e2XEKg7IssbNAP97Et4ptyI72nuOsRPHuP29y0JxUCtc7OTM
1Cwi1YARAQEA6mncSeuYW38Yz21/EoFxL0OoY/7OE2THqiNg6/f+vg8=
=ZXsX
-----END PGP SIGNATURE-----

Attachment: pgpZaUNhXDX0X.pgp
Description: PGP signature


--- End Message ---

Reply via email to