Security update for libosip2

SUSE Security Update: Security update for libosip2
Announcement ID: SUSE-SU-2017:1187-1
Rating: moderate
References: #1034570 #1034571 #1034572 #1034574
Affected Products:
  • SUSE Linux Enterprise Workstation Extension 12-SP2
  • SUSE Linux Enterprise Workstation Extension 12-SP1
  • SUSE Linux Enterprise Software Development Kit 12-SP2
  • SUSE Linux Enterprise Software Development Kit 12-SP1
  • SUSE Linux Enterprise Desktop 12-SP2
  • SUSE Linux Enterprise Desktop 12-SP1

  • An update that fixes four vulnerabilities is now available.

    Description:


    This update for libosip2 fixes several issues.

    These security issues were fixed:

    - CVE-2017-7853: In libosip2 a malformed SIP message could have lead to a
    heap buffer overflow in the msg_osip_body_parse() function defined in
    osipparser2/osip_message_parse.c, resulting in a remote DoS
    (bsc#1034570).
    - CVE-2016-10326: In libosip2 a malformed SIP message could have lead to a
    heap buffer overflow in the osip_body_to_str() function defined in
    osipparser2/osip_body.c, resulting in a remote DoS (bsc#1034571).
    - CVE-2016-10325: In libosip2 a malformed SIP message could have lead to a
    heap buffer overflow in the _osip_message_to_str() function defined in
    osipparser2/osip_message_to_str.c, resulting in a remote DoS
    (bsc#1034572).
    - CVE-2016-10324: In libosip2 a malformed SIP message could have lead to a
    heap buffer overflow in the osip_clrncpy() function defined in
    osipparser2/osip_port.c (bsc#1034574).

    Patch Instructions:

    To install this SUSE Security Update use YaST online_update.
    Alternatively you can run the command listed for your product:

    • SUSE Linux Enterprise Workstation Extension 12-SP2:
      zypper in -t patch SUSE-SLE-WE-12-SP2-2017-704=1
    • SUSE Linux Enterprise Workstation Extension 12-SP1:
      zypper in -t patch SUSE-SLE-WE-12-SP1-2017-704=1
    • SUSE Linux Enterprise Software Development Kit 12-SP2:
      zypper in -t patch SUSE-SLE-SDK-12-SP2-2017-704=1
    • SUSE Linux Enterprise Software Development Kit 12-SP1:
      zypper in -t patch SUSE-SLE-SDK-12-SP1-2017-704=1
    • SUSE Linux Enterprise Desktop 12-SP2:
      zypper in -t patch SUSE-SLE-DESKTOP-12-SP2-2017-704=1
    • SUSE Linux Enterprise Desktop 12-SP1:
      zypper in -t patch SUSE-SLE-DESKTOP-12-SP1-2017-704=1

    To bring your system up-to-date, use "zypper patch".

    Package List:

    • SUSE Linux Enterprise Workstation Extension 12-SP2 (x86_64):
      • libosip2-3.5.0-20.1
      • libosip2-debuginfo-3.5.0-20.1
      • libosip2-debugsource-3.5.0-20.1
    • SUSE Linux Enterprise Workstation Extension 12-SP1 (x86_64):
      • libosip2-3.5.0-20.1
      • libosip2-debuginfo-3.5.0-20.1
      • libosip2-debugsource-3.5.0-20.1
    • SUSE Linux Enterprise Software Development Kit 12-SP2 (aarch64 ppc64le s390x x86_64):
      • libosip2-3.5.0-20.1
      • libosip2-debuginfo-3.5.0-20.1
      • libosip2-debugsource-3.5.0-20.1
      • libosip2-devel-3.5.0-20.1
    • SUSE Linux Enterprise Software Development Kit 12-SP1 (ppc64le s390x x86_64):
      • libosip2-3.5.0-20.1
      • libosip2-debuginfo-3.5.0-20.1
      • libosip2-debugsource-3.5.0-20.1
      • libosip2-devel-3.5.0-20.1
    • SUSE Linux Enterprise Desktop 12-SP2 (x86_64):
      • libosip2-3.5.0-20.1
      • libosip2-debuginfo-3.5.0-20.1
      • libosip2-debugsource-3.5.0-20.1
    • SUSE Linux Enterprise Desktop 12-SP1 (x86_64):
      • libosip2-3.5.0-20.1
      • libosip2-debuginfo-3.5.0-20.1
      • libosip2-debugsource-3.5.0-20.1

    References: