Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2022-46871 impact on Kurento #23

Open
secnum opened this issue Apr 3, 2023 · 4 comments
Open

CVE-2022-46871 impact on Kurento #23

secnum opened this issue Apr 3, 2023 · 4 comments
Assignees

Comments

@secnum
Copy link

secnum commented Apr 3, 2023

Hi,

A vulnerability has been identified in the libusrsctp library, itself used in Kurento. Is Kurento affected by this vulnerability and if so, which versions?

@j1elo
Copy link
Member

j1elo commented Apr 4, 2023

Why do they hide what version is affected by the vulnerability? I went to that link (and several links from there) and still am wondering how to know if Kurento 6.x might be affected.

Kurento 7 uses the package libusrsctp1 from Ubuntu 20.04, so we'd rely on the Ubuntu security team to maintain security patches for it.

@j1elo j1elo self-assigned this Apr 4, 2023
@secnum
Copy link
Author

secnum commented Apr 5, 2023

Versions 0.9.5.0 and 0.9.4.0 of libusrsctp would not be affected (sctplab/usrsctp@939d48f) from email exchanges I've had with people at Mozilla.

@j1elo
Copy link
Member

j1elo commented Apr 5, 2023

Version in Ubuntu 20.04 is 0.9.3.0 so it seems it might and probably is affected:

# apt-cache policy libusrsctp1
libusrsctp1:
  Installed: (none)
  Candidate: 0.9.3.0+20190901-1
  Version table:
     0.9.3.0+20190901-1 500
        500 http://archive.ubuntu.com/ubuntu focal/universe amd64 Packages

The commit you linked is from July 2020, and the package version indicates that it was built on 2019, so this probably calls for opening a security ticket with the folks at Canonical. Would you be able to do that and let us know so we can track the state of this issue?

@secnum
Copy link
Author

secnum commented Apr 6, 2023

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants