Heap-based buffer overflow in Sofia-SIP - CVE-2023-32307
Published: May 26, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error within the stun_parse_attr_error_code() and stun_parse_attr_uint32() function. A remote attacker can send specially crafted STUN packets to the application, trigger a heap-based buffer overflow and perform a denial of service (DoS) attack.
Affected software
Debian Linux
Gentoo Linux
Ubuntu
openEuler
Fedora
sofia-sip-bin (Ubuntu package)
libsofia-sip-ua-glib3 (Ubuntu package)
libsofia-sip-ua0 (Ubuntu package)
sofia-sip (Debian package)
sofia-sip
sofia-sip-debuginfo
sofia-sip-debugsource
sofia-sip-devel
net-libs/sofia-sip
How to mitigate CVE-2023-32307
sofia-sip-bin (Ubuntu package) - addressed in versions Ubuntu Pro, 1.12.11+20110422.1+1e14eea~dfsg-4ubuntu1.23.04.1, 1.12.11+20110422.1+1e14eea~dfsg-4ubuntu1.23.10.1, 1.12.11+20110422.1-2.1+deb10u3ubuntu0.20.04.2, 1.12.11+20110422.1-2.1+deb10u3ubuntu0.22.04.2
libsofia-sip-ua-glib3 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.12.11+20110422.1+1e14eea~dfsg-4ubuntu1.23.04.1, 1.12.11+20110422.1+1e14eea~dfsg-4ubuntu1.23.10.1, 1.12.11+20110422.1-2.1+deb10u3ubuntu0.20.04.2, 1.12.11+20110422.1-2.1+deb10u3ubuntu0.22.04.2
libsofia-sip-ua0 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.12.11+20110422.1+1e14eea~dfsg-4ubuntu1.23.04.1, 1.12.11+20110422.1+1e14eea~dfsg-4ubuntu1.23.10.1, 1.12.11+20110422.1-2.1+deb10u3ubuntu0.20.04.2, 1.12.11+20110422.1-2.1+deb10u3ubuntu0.22.04.2
sofia-sip (Debian package) - update to 1.12.11+20110422.1-2.1+deb11u2
sofia-sip - update to 1.13.12-2
sofia-sip-debuginfo - update to 1.13.12-2
sofia-sip-debugsource - update to 1.13.12-2
sofia-sip-devel - update to 1.13.12-2
sofia-sip - update to 1.13.12-2.fc38
net-libs/sofia-sip - update to 1.13.16