Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 =========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2017.1479 libosip2 security update 14 June 2017 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: libosip2 Publisher: Debian Operating System: Linux variants Debian GNU/Linux 8 Impact/Access: Denial of Service -- Remote/Unauthenticated Resolution: Patch/Upgrade CVE Names: CVE-2017-7853 CVE-2016-10326 CVE-2016-10325 CVE-2016-10324 Original Bulletin: http://www.debian.org/security/2017/dsa-3879 Comment: This advisory references vulnerabilities in products which run on platforms other than Debian. It is recommended that administrators running libosip2 check for an updated version of the software for their operating system. - --------------------------BEGIN INCLUDED TEXT-------------------- - -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - - ------------------------------------------------------------------------- Debian Security Advisory DSA-3879-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff June 13, 2017 https://www.debian.org/security/faq - - ------------------------------------------------------------------------- Package : libosip2 CVE ID : CVE-2016-10324 CVE-2016-10325 CVE-2016-10326 CVE-2017-7853 Multiple security vulnerabilities have been found in oSIP, a library implementing the Session Initiation Protocol, which might result in denial of service through malformed SIP messages. For the stable distribution (jessie), these problems have been fixed in version 4.1.0-2+deb8u1. For the upcoming stable distribution (stretch), these problems have been fixed in version 4.1.0-2.1. For the unstable distribution (sid), these problems have been fixed in version 4.1.0-2.1. We recommend that you upgrade your libosip2 packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org - -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAllATZwACgkQEMKTtsN8 TjaLYQ//YVeSlMZICaqC0fDCtkfh2w3hwjjy1CmpAZ3MwcrS6EqRA8qTTcme5Z3Y wcLZlC+LtdRborm8ZRsvqABhJYFw6kWBeTxtuhUeeF4zE0A1fIwxLi3XuPxaRxHH NM9WDz9JkiAWf2OECbCvL3eGx5BSKdTl7WMrgAnTnppRjWyfZrSxqfr6zSaF+MgK 68ctFsGtJ17nb89YWXLVQzt9FIzOSYa6Un+5nm0whHvlGOqxXzKX9cv/tXbEL66C +WKhZHbjAUF5m9VywGgr5/UGcw50VHEF9aR0bmeV7ramez+kedsWlc0ypEcKjSFs +maAb+XLoiqmgGARuU1BOZT8H1LYg0cpY9NNXiOd9VnOijVQ9IcKj5n6sLZzC+Cp XwGOVJjpjnNe5NyQAGhk9Ta1Ky72Iddw/S2/zIJOEtl5FuHTCbet/NIu2EoNEQ4Q 0WJjPx099m7PsrUNADddIhQnnQti0uGD3cXzibKrSrTvfrb+ec8FgYtkqGbe64l/ TJZA1tYVuUwWMUn/dsJbnl0E8h1N/n739nd3SdGxmCa8+1rhOAUHsK84H9dfJT0P HoPPmbkohXuuI28ZWcl9JavuKBqpsKSzJ9A6cupL57r7CvoAJQhTzXiSSCnisotY BuQnBFaYzYBdLsNOOHHuEZdAoDpSrVSvFBOuKjdh6matYzbFpco= =hrHH - -----END PGP SIGNATURE----- - --------------------------END INCLUDED TEXT-------------------- You have received this e-mail bulletin as a result of your organisation's registration with AusCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. NOTE: Third Party Rights This security bulletin is provided as a service to AusCERT's members. As AusCERT did not write the document quoted above, AusCERT has had no control over its content. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the author's website to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: http://www.auscert.org.au/render.html?cid=1980 =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBWUC7Oox+lLeg9Ub1AQhp7Q//Vz6/kbSi41Qdec1BCDIAxlIJYiSLmziT V8wdgwknbdZabQcs8YJFBCk1Zxwp3q6srAFIo4A8MnEO8whHVU1kiW5IRBL1ZX29 gXBqDDFf1e/E8/BChxc3n7Ns8pSpQLnUmHKUtsE9S4Kroe11yRk7puHLpyyPW7MI uwSHBerN2D6mQ3yNFgJ3ShsX8shV0e/Ig+BN0p1Bt4THFF8JZwkz5i7NNMAwmt+4 GF9O2deiw+7ooNSMHLOC1X7yh1KyC1V2xONGhSzqgSUb/xHigd2JfKkartYrn8n2 SdyFKnHaCak+bg1FD7BNeVPWCTWi/MuuFmC/65kprmW49yIpOciiLnTlJS57amXE QhNTZ33YlNeTunaZdjqMf4lpsW4S8rv548jHSKtcYdTJlUJM+JefhoZvW1PTT+Yo k4S+QesW5DVkYASXdUDNv6Hg+HTunLgXERZBn/LHwZIXIV5Bul4Q2z7KevXSvo+K kApZij5D98xFOtE6VDX2Zhg4NAILR/ydbyx2T1Wakt3vPuglAuy0nXN3rwMktPbR nF4ZhZZQxU3ggVX4ayOaJOxuX7lTnwGKW3Gj62mbfYSo8FG0ZH4DF3g+NQ5AVyzo JYx/lcFOVC/4qmIsIzZZAZ/JOIEC9CF6s9ULpXwpBqgy48aXly2I+OfGa3qsN9CH H+IXVLK5WZA= =cHBa -----END PGP SIGNATURE-----