An issue was discovered in the libsofia-sip fork in drachtio-server before 0.8.20. It allows remote attackers to cause a denial of service (daemon crash) via a crafted UDP message that leads to a failure of the libsofia-sip-ua/tport/tport.c self assertion.
[
{
"id": "CVE-2022-47516-9a251d5e",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"332083738435093446771916377898312945208",
"255569788703833788770916166827643568470",
"165363004683784641494336107676070664102",
"153418132714500510589381506844718292084"
]
},
"deprecated": false,
"source": "https://github.com/drachtio/drachtio-server/commit/dd5946eb6525b1e11b3f6defda5725de4827cc71",
"signature_type": "Line",
"target": {
"file": "src/controller.cpp"
}
},
{
"id": "CVE-2022-47516-b06b2c85",
"signature_version": "v1",
"digest": {
"function_hash": "302820561589657871601387665499720260476",
"length": 3405.0
},
"deprecated": false,
"source": "https://github.com/drachtio/drachtio-server/commit/dd5946eb6525b1e11b3f6defda5725de4827cc71",
"signature_type": "Function",
"target": {
"file": "src/controller.cpp",
"function": "DrachtioController::initializeLogging"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-47516.json"