Bug#986815: CVE-2021-21375
Moritz Mühlenhoff
jmm at inutil.org
Mon Apr 12 12:31:48 BST 2021
retitle 986815 CVE-2021-21375 CVE-2020-15260
thanks
Am Mon, Apr 12, 2021 at 01:21:04PM +0200 schrieb Moritz Muehlenhoff:
> Source: ring
> Severity: grave
> Tags: security
> X-Debbugs-Cc: Debian Security Team <team at security.debian.org>
>
> ring bundles pjproject, so it's probably also affected by CVE-2021-21375?
>
> Advisory for pjproject is
> https://github.com/pjsip/pjproject/security/advisories/GHSA-hvq6-f89p-frvp
>
> Patch:
> https://github.com/pjsip/pjproject/commit/97b3d7addbaa720b7ddb0af9bf6f3e443e664365
And also CVE-2020-15260:
https://github.com/pjsip/pjproject/security/advisories/GHSA-8hcp-hm38-mfph
https://github.com/pjsip/pjproject/pull/2663
https://github.com/pjsip/pjproject/commit/67e46c1ac45ad784db5b9080f5ed8b133c122872
Cheers,
Moritz
More information about the Pkg-voip-maintainers
mailing list