I'm forwarding this to bug-guix@gnu.org so that it won't be forgotten.
Mark
-------------------- Start of forwarded message --------------------To: guix-devel@gnu.org
CVE-2021-21375 00:15PJSIP is a free and open source multimedia communication librarywritten in C language implementing standard based protocols such asSIP, SDP, RTP, STUN, TURN, and ICE. In PJSIP version 2.10 and earlier,after an initial INVITE has been sent, when two 183 responses arereceived, with the first one causing negotiation failure, a crash willoccur. This results in a denial of service.
CVE-2020-15260 00:15PJSIP is a free and open source multimedia communication librarywritten in C language implementing standard based protocols such asSIP, SDP, RTP, STUN, TURN, and ICE. In version 2.10 and earlier, PJSIPtransport can be reused if they have the same IP address + port +protocol. However, this is insufficient for secure transport since itlacks remote hostname authentication. Suppose we have created a TLSconnection to `sip.foo.com`, which has an IP address `100.1.1.1`. If wewant to create a TLS connection to another hostname, say `sip.bar.com`,which has the same IP address, then it will reuse that existingconnection, even though `100.1.1.1` does not have certificate toauthenticate as `sip.bar.com`. The vulnerability allows for an insecureinteraction without user awareness. It affects users who need access toconnections to different destinations that translate to the sameaddress, and allows man-in-the-middle attack if attacker can route aconnection to another destination such as in the case of DNS spoofing.
Upstream has not made a release yet, I advise we wait for a release ontheir end then upgrade. To be monitored.
-------------------- End of forwarded message --------------------