Bug 31588 - sofia-sip new security issue CVE-2022-47516
Summary: sofia-sip new security issue CVE-2022-47516
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2023-02-23 18:27 CET by David Walser
Modified: 2023-02-27 21:29 CET (History)
5 users (show)

See Also:
Source RPM: sofia-sip-1.13.12-1.mga9.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2023-02-23 18:27:13 CET
Debian-LTS has issued an advisory on February 22:
https://www.debian.org/lts/security/2023/dla-3334

The issue is fixed upstream in 1.13.14.

Mageia 8 is also affected.
David Walser 2023-02-23 18:28:28 CET

Whiteboard: (none) => MGA8TOO
Status comment: (none) => Fixed upstream in 1.13.14

Comment 1 David GEIGER 2023-02-24 05:00:14 CET
Done for both mga8 and Cauldron!

Freeze_move requested for Cauldron.

CC: (none) => geiger.david68210

Comment 2 David Walser 2023-02-24 19:01:03 CET
Cauldron package moved.

Mageia 8 package list:
libsofia-sip-devel-1.12.11-10.3.mga8
libsofia-sip0-1.12.11-10.3.mga8
sofia-sip-1.12.11-10.3.mga8
libsofia-sip-static-devel-1.12.11-10.3.mga8

from sofia-sip-1.12.11-10.3.mga8.src.rpm

Assignee: kde => qa-bugs
Whiteboard: MGA8TOO => (none)
Version: Cauldron => 8
Status comment: Fixed upstream in 1.13.14 => (none)

Comment 3 Herman Viaene 2023-02-25 10:53:16 CET
MGA8-64 MATE on Acer Aspire 5253.
At installation got  lib64sofia-sip-static-devel-1.12.11-10.3.mga8 not found in repos.
From info in MCC "It can be used as a building block for SIP client software for uses such as VoIP, IM, and many other real-time and person-to-person communication services." Just as TJ did in bug 30806 Comment 5.
Adventured into trying commands.
$ localinfo
<FQDN> maddr=[192.168.2.7] scope=site
<MACaddres>%wlp7s0 scope=link
127.0.0.1 scope=host
::1 scope=host
$ addrinfo
usage: addrinfo [-pnc46] <servicename> <domainname>
	-p query for passive open
	-n use numeric host names
	-c ask for canonic names
	-4 IPv4 only
	-6 IPv6 only (but including mapped IPv4 addresses)
$ sip-date 
Sat, 25 Feb 2023 09:42:15 GMT
other commands did not return anything usefull.
OK based on clean install (as in bug 30806) and the successful execution of the two commands.

Whiteboard: (none) => MGA8-64-OK
CC: (none) => herman.viaene

Comment 4 Thomas Andrews 2023-02-25 17:31:49 CET
Validating.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Dave Hodgins 2023-02-25 20:55:48 CET

Keywords: (none) => advisory
CC: (none) => davidwhodgins

Comment 5 Mageia Robot 2023-02-27 21:29:25 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2023-0072.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.