retitle 986815 CVE-2021-21375 CVE-2020-15260 thanks Am Mon, Apr 12, 2021 at 01:21:04PM +0200 schrieb Moritz Muehlenhoff: > Source: ring > Severity: grave > Tags: security > X-Debbugs-Cc: Debian Security Team <t...@security.debian.org> > > ring bundles pjproject, so it's probably also affected by CVE-2021-21375? > > Advisory for pjproject is > https://github.com/pjsip/pjproject/security/advisories/GHSA-hvq6-f89p-frvp > > Patch: > https://github.com/pjsip/pjproject/commit/97b3d7addbaa720b7ddb0af9bf6f3e443e664365
And also CVE-2020-15260: https://github.com/pjsip/pjproject/security/advisories/GHSA-8hcp-hm38-mfph https://github.com/pjsip/pjproject/pull/2663 https://github.com/pjsip/pjproject/commit/67e46c1ac45ad784db5b9080f5ed8b133c122872 Cheers, Moritz