Bug 1192703 (CVE-2021-43610) - VUL-1: CVE-2021-43610: belle-sip: before 5.0.20, an unauthenticated SIP message with an empty From header can crash the application
Summary: VUL-1: CVE-2021-43610: belle-sip: before 5.0.20, an unauthenticated SIP messa...
Status: RESOLVED FIXED
Alias: CVE-2021-43610
Product: openSUSE Distribution
Classification: openSUSE
Component: Security (show other bugs)
Version: Leap 15.3
Hardware: Other Other
: P4 - Low : Minor (vote)
Target Milestone: ---
Assignee: Giacomo Comes
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/314912/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2021-11-15 13:35 UTC by Thomas Leroy
Modified: 2024-07-23 09:48 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Thomas Leroy 2021-11-15 13:35:57 UTC
CVE-2021-43610

Belledonne Belle-sip before 5.0.20 can crash applications such as Linphone via
an invalid From header (request URI without a parameter) in an unauthenticated
SIP message, a different issue than CVE-2021-33056.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-43610
https://github.com/BelledonneCommunications/belle-sip/commit/d3f0651531e45e91c2e60f3a16a8b612802e5d2d
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-43610
https://github.com/BelledonneCommunications/belle-sip/compare/5.0.18...5.0.20
Comment 1 Thomas Leroy 2021-11-15 13:38:18 UTC
Affected codestreams:
- openSUSE:Backports:SLE-15-SP2:Update
- openSUSE:Backports:SLE-15-SP3:Update
- openSUSE:Leap:15.2:Update