Source: ring X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security
Hi, The following vulnerability was published for pjsig, which is bundled in ring: CVE-2023-38703[0]: | PJSIP is a free and open source multimedia communication library | written in C with high level API in C, C++, Java, C#, and Python | languages. SRTP is a higher level media transport which is stacked | upon a lower level media transport such as UDP and ICE. Currently a | higher level transport is not synchronized with its lower level | transport that may introduce use-after-free issue. This | vulnerability affects applications that have SRTP capability | (`PJMEDIA_HAS_SRTP` is set) and use underlying media transport other | than UDP. This vulnerability’s impact may range from unexpected | application termination to control flow hijack/memory corruption. | The patch is available as a commit in the master branch. https://github.com/pjsip/pjproject/security/advisories/GHSA-f76w-fh7c-pc66 https://github.com/pjsip/pjproject/commit/6dc9b8c181aff39845f02b4626e0812820d4ef0d (2.14) If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2023-38703 https://www.cve.org/CVERecord?id=CVE-2023-38703 Please adjust the affected versions in the BTS as needed.