SUSE-SU-2017:1187-1

Source
https://www.suse.com/support/update/announcement/2017/suse-su-20171187-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2017:1187-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2017:1187-1
Related
Published
2017-05-05T22:14:38Z
Modified
2025-05-02T04:05:05.205183Z
Upstream
Summary
Security update for libosip2
Details

This update for libosip2 fixes several issues.

These security issues were fixed:

  • CVE-2017-7853: In libosip2 a malformed SIP message could have lead to a heap buffer overflow in the msgosipbodyparse() function defined in osipparser2/osipmessage_parse.c, resulting in a remote DoS (bsc#1034570).
  • CVE-2016-10326: In libosip2 a malformed SIP message could have lead to a heap buffer overflow in the osipbodytostr() function defined in osipparser2/osipbody.c, resulting in a remote DoS (bsc#1034571).
  • CVE-2016-10325: In libosip2 a malformed SIP message could have lead to a heap buffer overflow in the osipmessagetostr() function defined in osipparser2/osipmessageto_str.c, resulting in a remote DoS (bsc#1034572).
  • CVE-2016-10324: In libosip2 a malformed SIP message could have lead to a heap buffer overflow in the osipclrncpy() function defined in osipparser2/osipport.c (bsc#1034574).
References

Affected packages

SUSE:Linux Enterprise Desktop 12 SP1 / libosip2

Package

Name
libosip2
Purl
pkg:rpm/suse/libosip2&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.5.0-20.1

Ecosystem specific

{
    "binaries": [
        {
            "libosip2": "3.5.0-20.1"
        }
    ]
}

SUSE:Linux Enterprise Desktop 12 SP2 / libosip2

Package

Name
libosip2
Purl
pkg:rpm/suse/libosip2&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.5.0-20.1

Ecosystem specific

{
    "binaries": [
        {
            "libosip2": "3.5.0-20.1"
        }
    ]
}

SUSE:Linux Enterprise Software Development Kit 12 SP1 / libosip2

Package

Name
libosip2
Purl
pkg:rpm/suse/libosip2&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.5.0-20.1

Ecosystem specific

{
    "binaries": [
        {
            "libosip2-devel": "3.5.0-20.1",
            "libosip2": "3.5.0-20.1"
        }
    ]
}

SUSE:Linux Enterprise Software Development Kit 12 SP2 / libosip2

Package

Name
libosip2
Purl
pkg:rpm/suse/libosip2&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.5.0-20.1

Ecosystem specific

{
    "binaries": [
        {
            "libosip2-devel": "3.5.0-20.1",
            "libosip2": "3.5.0-20.1"
        }
    ]
}

SUSE:Linux Enterprise Workstation Extension 12 SP1 / libosip2

Package

Name
libosip2
Purl
pkg:rpm/suse/libosip2&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.5.0-20.1

Ecosystem specific

{
    "binaries": [
        {
            "libosip2": "3.5.0-20.1"
        }
    ]
}

SUSE:Linux Enterprise Workstation Extension 12 SP2 / libosip2

Package

Name
libosip2
Purl
pkg:rpm/suse/libosip2&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.5.0-20.1

Ecosystem specific

{
    "binaries": [
        {
            "libosip2": "3.5.0-20.1"
        }
    ]
}