Signalwire
signalwire
6 CVEs • 2 products
Products (2)
Click to collapseToggle
Products (2)
Click to collapse
CVEs (6)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Signalwire2Debian Linux Sofia SipJan 14, 2025 May 26, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Sofia-SIP is an open-source SIP User-Agent library, compliant with the IETF RFC3261 specification. Referring to [GHSA-8599-x7rq-fr54](https://github.com/freeswitch/sofia-sip/security/advisories/GHSA-8599-x7rq-fr54), seve...Show more |
Sofia-SIP is an open-source SIP User-Agent library, compliant with the IETF RFC3261 specification. In affected versions Sofia-SIP **lacks both message length and attributes length checks** when it handles STUN packets, l...Show more |
2Debian Signalwire2Debian Linux Sofia SipNov 21, 2024 May 31, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, when parsing each line of a sdp message, `rest = record + 2` will access the memory behind `\0` and cause an out-...Show more |
2Debian Signalwire2Debian Linux Sofia SipNov 21, 2024 May 31, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, an attacker can send a message with evil sdp to FreeSWITCH, which may cause crash. This type of crash may be caus...Show more |
2Debian Signalwire2Debian Linux Sofia SipNov 21, 2024 May 31, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, an attacker can send a message with evil sdp to FreeSWITCH, which may cause a crash. This type of crash may be ca...Show more |
An issue was discovered in function sofia_handle_sip_i_notify in sofia.c in SignalWire freeswitch before 1.10.6, may allow attackers to view sensitive information due to an uninitialized value. |