Debian 12 — libosip2 — multiple vulnerabilities (5 CVEs) — patch and remediation guide
🟡 Medium ⏱ 10–30 min Last verified: 9 February 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read • Source: Debian Security Tracker Related CVEs: CVE-2016-10324 CVE-2016-10325 CVE-2016-10326 CVE-2017-7853 CVE-2022-41550 Upstream summary: In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_clrncpy() function […]