Bug#1036697: asterisk: CVE-2023-27585

2023-12-13 Thread Faidon Liambotis
Dear Jonas, On Mon, Aug 07, 2023 at 03:51:51PM +0300, Faidon Liambotis wrote: > Dear maintainer, security team, > > (See #1032092 for a similar bug with an almost equivalent response) I've seen that you've uploaded a couple new upstream releases of Asterisk in the time since my last response. G

Bug#1036697: asterisk: CVE-2023-27585

2023-08-07 Thread Faidon Liambotis
Dear maintainer, security team, (See #1032092 for a similar bug with an almost equivalent response) The changelog for the asterisk 1:20.4.0~dfsg+~cs6.13.40431414-1 upload dated 2023-08-04, currently in unstable, mentions: >+ fixate component pjproject at upstream release 2.13.1 The sources s

Bug#1036697: asterisk: CVE-2023-27585

2023-05-24 Thread Moritz Mühlenhoff
Source: asterisk X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerability was published for asterisk. CVE-2023-27585[0]: | PJSIP is a free and open source multimedia communication library | written in C. A buffer overflow vulnerability in versions 2.1