UBUNTU-CVE-2023-32307

Source
https://ubuntu.com/security/CVE-2023-32307
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-32307.json
JSON Data
https://api.test.osv.dev/v1/vulns/UBUNTU-CVE-2023-32307
Related
Published
2023-05-26T23:15:00Z
Modified
2025-01-13T10:24:21Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Sofia-SIP is an open-source SIP User-Agent library, compliant with the IETF RFC3261 specification. Referring to GHSA-8599-x7rq-fr54, several other potential heap-over-flow and integer-overflow in stunparseattrerrorcode and stunparseattruint32 were found because the lack of attributes length check when Sofia-SIP handles STUN packets. The previous patch of GHSA-8599-x7rq-fr54 fixed the vulnerability when attrtype did not match the enum value, but there are also vulnerabilities in the handling of other valid cases. The OOB read and integer-overflow made by attacker may lead to crash, high consumption of memory or even other more serious consequences. These issue have been addressed in version 1.13.15. Users are advised to upgrade.

References

Affected packages

Ubuntu:Pro:16.04:LTS / sofia-sip

Package

Name
sofia-sip
Purl
pkg:deb/ubuntu/sofia-sip@1.12.11+20110422.1-2.1+deb10u3ubuntu0.16.04.1~esm2?arch=source&distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.12.11+20110422.1-2.1+deb10u3ubuntu0.16.04.1~esm2

Affected versions

1.*

1.12.11+20110422.1-2ubuntu1
1.12.11+20110422.1-2.1+deb10u3ubuntu0.16.04.1~esm1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "1.12.11+20110422.1-2.1+deb10u3ubuntu0.16.04.1~esm2",
            "binary_name": "libsofia-sip-ua-dev"
        },
        {
            "binary_version": "1.12.11+20110422.1-2.1+deb10u3ubuntu0.16.04.1~esm2",
            "binary_name": "libsofia-sip-ua-glib-dev"
        },
        {
            "binary_version": "1.12.11+20110422.1-2.1+deb10u3ubuntu0.16.04.1~esm2",
            "binary_name": "libsofia-sip-ua-glib3"
        },
        {
            "binary_version": "1.12.11+20110422.1-2.1+deb10u3ubuntu0.16.04.1~esm2",
            "binary_name": "libsofia-sip-ua-glib3-dbgsym"
        },
        {
            "binary_version": "1.12.11+20110422.1-2.1+deb10u3ubuntu0.16.04.1~esm2",
            "binary_name": "libsofia-sip-ua0"
        },
        {
            "binary_version": "1.12.11+20110422.1-2.1+deb10u3ubuntu0.16.04.1~esm2",
            "binary_name": "libsofia-sip-ua0-dbgsym"
        },
        {
            "binary_version": "1.12.11+20110422.1-2.1+deb10u3ubuntu0.16.04.1~esm2",
            "binary_name": "sofia-sip-bin"
        },
        {
            "binary_version": "1.12.11+20110422.1-2.1+deb10u3ubuntu0.16.04.1~esm2",
            "binary_name": "sofia-sip-bin-dbgsym"
        },
        {
            "binary_version": "1.12.11+20110422.1-2.1+deb10u3ubuntu0.16.04.1~esm2",
            "binary_name": "sofia-sip-doc"
        }
    ]
}

Ubuntu:Pro:18.04:LTS / sofia-sip

Package

Name
sofia-sip
Purl
pkg:deb/ubuntu/sofia-sip@1.12.11+20110422.1-2.1+deb10u3ubuntu0.18.04.1~esm1?arch=source&distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.12.11+20110422.1-2.1+deb10u3ubuntu0.18.04.1~esm1

Affected versions

1.*

1.12.11+20110422.1-2.1
1.12.11+20110422.1-2.1build1
1.12.11+20110422.1-2.1+deb10u3build0.18.04.1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "1.12.11+20110422.1-2.1+deb10u3ubuntu0.18.04.1~esm1",
            "binary_name": "libsofia-sip-ua-dev"
        },
        {
            "binary_version": "1.12.11+20110422.1-2.1+deb10u3ubuntu0.18.04.1~esm1",
            "binary_name": "libsofia-sip-ua-glib-dev"
        },
        {
            "binary_version": "1.12.11+20110422.1-2.1+deb10u3ubuntu0.18.04.1~esm1",
            "binary_name": "libsofia-sip-ua-glib3"
        },
        {
            "binary_version": "1.12.11+20110422.1-2.1+deb10u3ubuntu0.18.04.1~esm1",
            "binary_name": "libsofia-sip-ua-glib3-dbgsym"
        },
        {
            "binary_version": "1.12.11+20110422.1-2.1+deb10u3ubuntu0.18.04.1~esm1",
            "binary_name": "libsofia-sip-ua0"
        },
        {
            "binary_version": "1.12.11+20110422.1-2.1+deb10u3ubuntu0.18.04.1~esm1",
            "binary_name": "libsofia-sip-ua0-dbgsym"
        },
        {
            "binary_version": "1.12.11+20110422.1-2.1+deb10u3ubuntu0.18.04.1~esm1",
            "binary_name": "sofia-sip-bin"
        },
        {
            "binary_version": "1.12.11+20110422.1-2.1+deb10u3ubuntu0.18.04.1~esm1",
            "binary_name": "sofia-sip-bin-dbgsym"
        },
        {
            "binary_version": "1.12.11+20110422.1-2.1+deb10u3ubuntu0.18.04.1~esm1",
            "binary_name": "sofia-sip-doc"
        }
    ]
}

Ubuntu:20.04:LTS / sofia-sip

Package

Name
sofia-sip
Purl
pkg:deb/ubuntu/sofia-sip@1.12.11+20110422.1-2.1+deb10u3ubuntu0.20.04.2?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.12.11+20110422.1-2.1+deb10u3ubuntu0.20.04.2

Affected versions

1.*

1.12.11+20110422.1-2.1build1
1.12.11+20110422.1-2.1+deb10u3ubuntu0.20.04.1

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "1.12.11+20110422.1-2.1+deb10u3ubuntu0.20.04.2",
            "binary_name": "libsofia-sip-ua-dev"
        },
        {
            "binary_version": "1.12.11+20110422.1-2.1+deb10u3ubuntu0.20.04.2",
            "binary_name": "libsofia-sip-ua-glib-dev"
        },
        {
            "binary_version": "1.12.11+20110422.1-2.1+deb10u3ubuntu0.20.04.2",
            "binary_name": "libsofia-sip-ua-glib3"
        },
        {
            "binary_version": "1.12.11+20110422.1-2.1+deb10u3ubuntu0.20.04.2",
            "binary_name": "libsofia-sip-ua-glib3-dbgsym"
        },
        {
            "binary_version": "1.12.11+20110422.1-2.1+deb10u3ubuntu0.20.04.2",
            "binary_name": "libsofia-sip-ua0"
        },
        {
            "binary_version": "1.12.11+20110422.1-2.1+deb10u3ubuntu0.20.04.2",
            "binary_name": "libsofia-sip-ua0-dbgsym"
        },
        {
            "binary_version": "1.12.11+20110422.1-2.1+deb10u3ubuntu0.20.04.2",
            "binary_name": "sofia-sip-bin"
        },
        {
            "binary_version": "1.12.11+20110422.1-2.1+deb10u3ubuntu0.20.04.2",
            "binary_name": "sofia-sip-bin-dbgsym"
        },
        {
            "binary_version": "1.12.11+20110422.1-2.1+deb10u3ubuntu0.20.04.2",
            "binary_name": "sofia-sip-doc"
        }
    ]
}

Ubuntu:22.04:LTS / sofia-sip

Package

Name
sofia-sip
Purl
pkg:deb/ubuntu/sofia-sip@1.12.11+20110422.1-2.1+deb10u3ubuntu0.22.04.2?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.12.11+20110422.1-2.1+deb10u3ubuntu0.22.04.2

Affected versions

1.*

1.12.11+20110422.1-2.1ubuntu1
1.12.11+20110422.1-2.1ubuntu2
1.12.11+20110422.1-2.1+deb10u3ubuntu0.22.04.1

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "1.12.11+20110422.1-2.1+deb10u3ubuntu0.22.04.2",
            "binary_name": "libsofia-sip-ua-dev"
        },
        {
            "binary_version": "1.12.11+20110422.1-2.1+deb10u3ubuntu0.22.04.2",
            "binary_name": "libsofia-sip-ua-glib-dev"
        },
        {
            "binary_version": "1.12.11+20110422.1-2.1+deb10u3ubuntu0.22.04.2",
            "binary_name": "libsofia-sip-ua-glib3"
        },
        {
            "binary_version": "1.12.11+20110422.1-2.1+deb10u3ubuntu0.22.04.2",
            "binary_name": "libsofia-sip-ua-glib3-dbgsym"
        },
        {
            "binary_version": "1.12.11+20110422.1-2.1+deb10u3ubuntu0.22.04.2",
            "binary_name": "libsofia-sip-ua0"
        },
        {
            "binary_version": "1.12.11+20110422.1-2.1+deb10u3ubuntu0.22.04.2",
            "binary_name": "libsofia-sip-ua0-dbgsym"
        },
        {
            "binary_version": "1.12.11+20110422.1-2.1+deb10u3ubuntu0.22.04.2",
            "binary_name": "sofia-sip-bin"
        },
        {
            "binary_version": "1.12.11+20110422.1-2.1+deb10u3ubuntu0.22.04.2",
            "binary_name": "sofia-sip-bin-dbgsym"
        },
        {
            "binary_version": "1.12.11+20110422.1-2.1+deb10u3ubuntu0.22.04.2",
            "binary_name": "sofia-sip-doc"
        }
    ]
}