Bugzilla – Bug 1192703
VUL-1: CVE-2021-43610: belle-sip: before 5.0.20, an unauthenticated SIP message with an empty From header can crash the application
Last modified: 2024-07-23 09:48:54 UTC
CVE-2021-43610 Belledonne Belle-sip before 5.0.20 can crash applications such as Linphone via an invalid From header (request URI without a parameter) in an unauthenticated SIP message, a different issue than CVE-2021-33056. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-43610 https://github.com/BelledonneCommunications/belle-sip/commit/d3f0651531e45e91c2e60f3a16a8b612802e5d2d http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-43610 https://github.com/BelledonneCommunications/belle-sip/compare/5.0.18...5.0.20
Affected codestreams: - openSUSE:Backports:SLE-15-SP2:Update - openSUSE:Backports:SLE-15-SP3:Update - openSUSE:Leap:15.2:Update