• [SECURITY] [DSA 4292-1] kamailio security update

    From Salvatore Bonaccorso@1:229/2 to All on Tue Sep 11 22:20:02 2018
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-4292-1 [email protected] https://www.debian.org/security/ Salvatore Bonaccorso September 11, 2018 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : kamailio
    CVE ID : CVE-2018-16657
    Debian Bug : 908324

    Henning Westerholt discovered a flaw related to the Via header
    processing in kamailio, a very fast, dynamic and configurable SIP
    server. An unauthenticated attacker can take advantage of this flaw to
    mount a denial of service attack via a specially crafted SIP message
    with an invalid Via header.

    For the stable distribution (stretch), this problem has been fixed in
    version 4.4.4-2+deb9u3.

    We recommend that you upgrade your kamailio packages.

    For the detailed security status of kamailio please refer to its
    security tracker page at:
    https://security-tracker.debian.org/tracker/kamailio

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----

    iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAluYH5xfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0QjPw/9HrB5M5SaEqLQCpYwT2HQBDezSFxq/VBx8dF61bbxfZxbbax0QsFKdq4V +a40CqKG9vx5zQ0+lgNPo+wihxYNl50Up5eWYiHS5ROiQxH11vHUsz81VLjF1eXk ayc3c8m1PtbMI1sssjQF54tZ+BBFTOrCXrn05OZCFejUSI686ApFdEBiRFUuwJV3 KpnIEcbZbcsjfoXJO5oq168Q8N4j9XCKyveL14ULinK5HlmVPOvmiWqgkJh3aroX RnU4axrard6QzI+Bf7cAuKo/16MjkdN+stmhs+MwKO/XDQkeFp31vObzzgV955/A eH9plGCpcamdkFKKclvnWXW4jrj4r0pAuXWmcPJQ9YcaaPEwbPXGOt8syFGaUToY bzKu0ol3zZp/Xez08cooz2j5c5fVC+v+kdtLFbxwEnQGxOMBGSOSEO6SPNyd2dxa t/3pCbXTVciAUtwFmKEKSP1LUG78PO67Dt6jMvqUrUXlb6WO1kWBodKSe0DnIzzz Id3ixBLl0kn96Q0HKRegvuDtwYcyjIaDTkGvjq4DCXXlD8xeCUe1nIWAlTwGuo+X z20dZ+0mhHizIex4uGXeCo/9Z4Nk+tJgm6errqqEpQjxw59uNud6gI8Fe5eZe7DH XYlKXWVtezEZ71qptiZWyOs6XSkUUEmiGD1bp4AcwEP2aMbcoaY=
    =obkn
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)