Bug#986815: CVE-2021-21375

Moritz Mühlenhoff jmm at inutil.org
Mon Apr 12 12:31:48 BST 2021


retitle 986815 CVE-2021-21375 CVE-2020-15260
thanks

Am Mon, Apr 12, 2021 at 01:21:04PM +0200 schrieb Moritz Muehlenhoff:
> Source: ring
> Severity: grave
> Tags: security
> X-Debbugs-Cc: Debian Security Team <team at security.debian.org>
> 
> ring bundles pjproject, so it's probably also affected by CVE-2021-21375?
> 
> Advisory for pjproject is
> https://github.com/pjsip/pjproject/security/advisories/GHSA-hvq6-f89p-frvp
> 
> Patch:
> https://github.com/pjsip/pjproject/commit/97b3d7addbaa720b7ddb0af9bf6f3e443e664365

And also CVE-2020-15260:
https://github.com/pjsip/pjproject/security/advisories/GHSA-8hcp-hm38-mfph

https://github.com/pjsip/pjproject/pull/2663
https://github.com/pjsip/pjproject/commit/67e46c1ac45ad784db5b9080f5ed8b133c122872
 
Cheers,
        Moritz



More information about the Pkg-voip-maintainers mailing list