Bug#869404: resiprocate: CVE-2017-11521: Adding too many media connections may lead to memory exhaustion

2017-10-18 Thread Petter Reinholdtsen
Control: tags -1 + patch This issue has caused resiprocate to be thrown out of testing. This is unfortunate, as it is used by the FreedomBox, and thus it is no longer possible to set up a Buster based Freedombox with SIP support. According to the upstream git repo, the 5 line patch in https://gi

Bug#869404: resiprocate: CVE-2017-11521: Adding too many media connections may lead to memory exhaustion

2017-09-30 Thread Moritz Muehlenhoff
On Sun, Jul 23, 2017 at 07:55:20AM +0200, Salvatore Bonaccorso wrote: > Source: resiprocate > Version: 1:1.9.7-5 > Severity: grave > Tags: upstream security > Forwarded: https://github.com/resiprocate/resiprocate/pull/88 > > Hi, > > the following vulnerability was published for resiprocate. > >

Bug#869404: resiprocate: CVE-2017-11521: Adding too many media connections may lead to memory exhaustion

2017-07-22 Thread Salvatore Bonaccorso
Source: resiprocate Version: 1:1.9.7-5 Severity: grave Tags: upstream security Forwarded: https://github.com/resiprocate/resiprocate/pull/88 Hi, the following vulnerability was published for resiprocate. CVE-2017-11521[0]: | The SdpContents::Session::Medium::parse function in | resip/stack/SdpCo