Source: asterisk X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security
Hi, The following vulnerabilities were published for asterisk. CVE-2022-23537[0]: | PJSIP is a free and open source multimedia communication library | written in C language implementing standard based protocols such as | SIP, SDP, RTP, STUN, TURN, and ICE. Buffer overread is possible when | parsing a specially crafted STUN message with unknown attribute. The | vulnerability affects applications that uses STUN including PJNATH and | PJSUA-LIB. The patch is available as a commit in the master branch | (2.13.1). https://github.com/pjsip/pjproject/security/advisories/GHSA-9pfh-r8x4-w26w https://github.com/pjsip/pjproject/commit/d8440f4d711a654b511f50f79c0445b26f9dd1e1 CVE-2022-23547[1]: | PJSIP is a free and open source multimedia communication library | written in C language implementing standard based protocols such as | SIP, SDP, RTP, STUN, TURN, and ICE. This issue is similar to | GHSA-9pfh-r8x4-w26w. Possible buffer overread when parsing a certain | STUN message. The vulnerability affects applications that uses STUN | including PJNATH and PJSUA-LIB. The patch is available as commit in | the master branch. https://github.com/pjsip/pjproject/security/advisories/GHSA-9pfh-r8x4-w26w https://github.com/pjsip/pjproject/commit/d8440f4d711a654b511f50f79c0445b26f9dd1e1 https://github.com/pjsip/pjproject/security/advisories/GHSA-cxwq-5g9x-x7fr https://github.com/pjsip/pjproject/commit/bc4812d31a67d5e2f973fbfaf950d6118226cf36 CVE-2022-39269[2]: | PJSIP is a free and open source multimedia communication library | written in C. When processing certain packets, PJSIP may incorrectly | switch from using SRTP media transport to using basic RTP upon SRTP | restart, causing the media to be sent insecurely. The vulnerability | impacts all PJSIP users that use SRTP. The patch is available as | commit d2acb9a in the master branch of the project and will be | included in version 2.13. Users are advised to manually patch or to | upgrade. There are no known workarounds for this vulnerability. https://github.com/pjsip/pjproject/security/advisories/GHSA-wx5m-cj97-4wwg https://github.com/pjsip/pjproject/commit/d2acb9af4e27b5ba75d658690406cec9c274c5cc If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2022-23537 https://www.cve.org/CVERecord?id=CVE-2022-23537 [1] https://security-tracker.debian.org/tracker/CVE-2022-23547 https://www.cve.org/CVERecord?id=CVE-2022-23547 [2] https://security-tracker.debian.org/tracker/CVE-2022-39269 https://www.cve.org/CVERecord?id=CVE-2022-39269 Please adjust the affected versions in the BTS as needed.