MGASA-2013-0279
Dashboard / Vulnerabilities / MGASA-2013-0279
Summary: Updated freeswitch packages fix security vulnerability
Details: In FreeSWITCH before 1.2.12, if the routing configuration includes regular expressions that don't constrain the length of the input, buffer overflows are possible. Since these regular expressions are matched against untrusted input, remote code execution may be possible (CVE-2013-2238).
References: https://advisories.mageia.org/MGASA-2013-0279.html, https://bugs.mageia.org/show_bug.cgi?id=10743, http://openwall.com/lists/oss-security/2013/07/01/11, http://jira.freeswitch.org/browse/FS-5566
Affected packages
Package
Name: freeswitch
Purl: pkg:rpm/mageia/freeswitch?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -1.2.12-6.mga3
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
