The SdpContents::Session::Medium::parse function in resip/stack/SdpContents.cxx in reSIProcate 1.10.2 allows remote attackers to cause a denial of service (memory consumption) by triggering many media connections.
{
"binaries": [
{
"binary_version": "1:1.10.1-2ubuntu1",
"binary_name": "librecon-1.10"
},
{
"binary_version": "1:1.10.1-2ubuntu1",
"binary_name": "librecon-1.10-dev"
},
{
"binary_version": "1:1.10.1-2ubuntu1",
"binary_name": "libresiprocate-1.10"
},
{
"binary_version": "1:1.10.1-2ubuntu1",
"binary_name": "libresiprocate-1.10-dev"
},
{
"binary_version": "1:1.10.1-2ubuntu1",
"binary_name": "libresiprocate-turn-client-1.10"
},
{
"binary_version": "1:1.10.1-2ubuntu1",
"binary_name": "libresiprocate-turn-client-1.10-dev"
},
{
"binary_version": "1:1.10.1-2ubuntu1",
"binary_name": "repro"
},
{
"binary_version": "1:1.10.1-2ubuntu1",
"binary_name": "resiprocate-turn-server"
},
{
"binary_version": "1:1.10.1-2ubuntu1",
"binary_name": "resiprocate-turn-server-psql"
},
{
"binary_version": "1:1.10.1-2ubuntu1",
"binary_name": "sipdialer"
}
]
}
{
"binaries": [
{
"binary_version": "1:1.11.0~beta5-1",
"binary_name": "librecon-1.11"
},
{
"binary_version": "1:1.11.0~beta5-1",
"binary_name": "librecon-1.11-dev"
},
{
"binary_version": "1:1.11.0~beta5-1",
"binary_name": "libresiprocate-1.11"
},
{
"binary_version": "1:1.11.0~beta5-1",
"binary_name": "libresiprocate-1.11-dev"
},
{
"binary_version": "1:1.11.0~beta5-1",
"binary_name": "libresiprocate-turn-client-1.11"
},
{
"binary_version": "1:1.11.0~beta5-1",
"binary_name": "libresiprocate-turn-client-1.11-dev"
},
{
"binary_version": "1:1.11.0~beta5-1",
"binary_name": "repro"
},
{
"binary_version": "1:1.11.0~beta5-1",
"binary_name": "resiprocate-turn-server"
},
{
"binary_version": "1:1.11.0~beta5-1",
"binary_name": "resiprocate-turn-server-psql"
},
{
"binary_version": "1:1.11.0~beta5-1",
"binary_name": "sipdialer"
},
{
"binary_version": "1:1.11.0~beta5-1",
"binary_name": "telepathy-resiprocate"
}
]
}