An issue was discovered in the libsofia-sip fork in drachtio-server before 0.8.20. It allows remote attackers to cause a denial of service (daemon crash) via a crafted UDP message that leads to a failure of the libsofia-sip-ua/tport/tport.c self assertion.
[
{
"source": "https://github.com/davehorton/sofia-sip/commit/13b2a135287caa2d67ac6cd5155626821e25b377",
"id": "CVE-2022-47516-6838b271",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "libsofia-sip-ua/tport/tport.c"
},
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"137665327021306405935673177103996540739",
"222660642482478647502609743690131795640",
"126945473246565109207045912794547003621",
"75899966100980029990415126950327193709"
]
}
},
{
"source": "https://github.com/davehorton/sofia-sip/commit/13b2a135287caa2d67ac6cd5155626821e25b377",
"id": "CVE-2022-47516-b0dbb540",
"deprecated": false,
"signature_version": "v1",
"target": {
"function": "tport_tsend",
"file": "libsofia-sip-ua/tport/tport.c"
},
"signature_type": "Function",
"digest": {
"length": 3356.0,
"function_hash": "9098198435050197295798369122218213473"
}
}
]
[
{
"source": "https://github.com/drachtio/drachtio-server/commit/dd5946eb6525b1e11b3f6defda5725de4827cc71",
"id": "CVE-2022-47516-9a251d5e",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "src/controller.cpp"
},
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"332083738435093446771916377898312945208",
"255569788703833788770916166827643568470",
"165363004683784641494336107676070664102",
"153418132714500510589381506844718292084"
]
}
},
{
"source": "https://github.com/drachtio/drachtio-server/commit/dd5946eb6525b1e11b3f6defda5725de4827cc71",
"id": "CVE-2022-47516-b06b2c85",
"deprecated": false,
"signature_version": "v1",
"target": {
"function": "DrachtioController::initializeLogging",
"file": "src/controller.cpp"
},
"signature_type": "Function",
"digest": {
"length": 3405.0,
"function_hash": "302820561589657871601387665499720260476"
}
}
]