[Git][security-tracker-team/security-tracker][master] Update status for CVE-2025-53399/rtpengine
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sun Aug 3 19:34:19 BST 2025
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
54f6451e by Salvatore Bonaccorso at 2025-08-03T20:33:37+02:00
Update status for CVE-2025-53399/rtpengine
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -397,9 +397,10 @@ CVE-2023-32251 (A vulnerability has been identified in the Linux kernel's ksmbd
NOTE: https://git.kernel.org/linus/b096d97f47326b1e2dbdef1c91fab69ffda54d17 (6.4-rc1)
NOTE: https://www.zerodayinitiative.com/advisories/ZDI-23-699/
CVE-2025-53399 (In Sipwise rtpengine before 13.4.1.1, an origin-validation error in th ...)
- - rtpengine <unfixed> (bug #1110316)
+ - rtpengine 12.5.1.35-1 (bug #1110316)
NOTE: https://www.openwall.com/lists/oss-security/2025/07/31/1
NOTE: https://github.com/EnableSecurity/advisories/tree/master/ES2025-01-rtpengine-improper-behavior-bleed-inject
+ NOTE: Fixed by: https://github.com/sipwise/rtpengine/commits/a68f3dd1e65ba1d81bb8996d7bfab82641f20b50 (mr12.5.1.35)
NOTE: https://github.com/sipwise/rtpengine/commits/rfuchs/security/ (MT#62735)
CVE-2025-8426 (Marvell QConvergeConsole compressConfigFiles Directory Traversal Infor ...)
NOT-FOR-US: Marvell
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/54f6451eb696c50a0c7a8fe74a11e2ef38db7725
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/54f6451eb696c50a0c7a8fe74a11e2ef38db7725
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250803/58652127/attachment.htm>
More information about the debian-security-tracker-commits
mailing list