Debian Libosip2 vulnerabilities
5 known vulnerabilities affecting debian/libosip2.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH3MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2016-10324P3CRITICALCVSS 9.8fixed in libosip2 4.1.0-2.1 (bookworm)2016
CVE-2016-10324 [CRITICAL] CVE-2016-10324: libosip2 - In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer...
In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_clrncpy() function defined in osipparser2/osip_port.c.
Scope: local
bookworm: resolved (fixed in 4.1.0-2.1)
bullseye: resolved (fixed in 4.1.0-2.1)
forky: resolved (fixed in 4.1.0-2.1)
sid: resolved (fixed in 4.1.0-2.1)
trixie: resolved (fixed in 4.1.0-2.1)
debian
CVE-2017-7853P3HIGHCVSS 7.5fixed in libosip2 4.1.0-2.1 (bookworm)2017
CVE-2017-7853 [HIGH] CVE-2017-7853: libosip2 - In libosip2 in GNU oSIP 4.1.0 and 5.0.0, a malformed SIP message can lead to a h...
In libosip2 in GNU oSIP 4.1.0 and 5.0.0, a malformed SIP message can lead to a heap buffer overflow in the msg_osip_body_parse() function defined in osipparser2/osip_message_parse.c, resulting in a remote DoS.
Scope: local
bookworm: resolved (fixed in 4.1.0-2.1)
bullseye: resolved (fixed in 4.1.0-2.1)
forky: resolved (fixed in 4.1.0-2.1)
sid: resolved (fixed in 4.1.0
debian
CVE-2016-10326P4HIGHCVSS 7.5fixed in libosip2 4.1.0-2.1 (bookworm)2016
CVE-2016-10326 [HIGH] CVE-2016-10326: libosip2 - In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer...
In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_body_to_str() function defined in osipparser2/osip_body.c, resulting in a remote DoS.
Scope: local
bookworm: resolved (fixed in 4.1.0-2.1)
bullseye: resolved (fixed in 4.1.0-2.1)
forky: resolved (fixed in 4.1.0-2.1)
sid: resolved (fixed in 4.1.0-2.1)
trixie: resolv
debian
CVE-2016-10325P4HIGHCVSS 7.5fixed in libosip2 4.1.0-2.1 (bookworm)2016
CVE-2016-10325 [HIGH] CVE-2016-10325: libosip2 - In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer...
In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the _osip_message_to_str() function defined in osipparser2/osip_message_to_str.c, resulting in a remote DoS.
Scope: local
bookworm: resolved (fixed in 4.1.0-2.1)
bullseye: resolved (fixed in 4.1.0-2.1)
forky: resolved (fixed in 4.1.0-2.1)
sid: resolved (fixed in 4.1.0-2.1)
debian
CVE-2022-41550P4MEDIUMCVSS 6.5fixed in libosip2 5.3.0-2.1 (bookworm)2022
CVE-2022-41550 [MEDIUM] CVE-2022-41550: libosip2 - GNU oSIP v5.3.0 was discovered to contain an integer overflow via the component ...
GNU oSIP v5.3.0 was discovered to contain an integer overflow via the component osip_body_parse_header.
Scope: local
bookworm: resolved (fixed in 5.3.0-2.1)
bullseye: open
forky: resolved (fixed in 5.3.0-2.1)
sid: resolved (fixed in 5.3.0-2.1)
trixie: resolved (fixed in 5.3.0-2.1)
debian