Fabrice Fontaine
2a62ff8274
package/libpjsip: security bump to version 2.12.1
Security Issue:
- Potential buffer overflow in pjsip_auth_create_digest()
(GHSA-73f7-48m9-w662 a.k.a. CVE-2022-24754)
- Denial-of-service in XML parsing due to an infinite loop
(GHSA-5x45-qp78-g4p4 a.k.a. CVE-2022-24763)
- Potential stack buffer overflow when printing SDP into a buffer
(GHSA-f5qg-pqcg-765m a.k.a. CVE-2022-24764)
- Potential out-of-bound read/write when parsing RTCP FB RPSI
(GHSA-vhxv-phmx-g52q a.k.a. CVE-2022-24786)
- Potential infinite loop when parsing WAV format file
(GHSA-rwgw-vwxg-q799 a.k.a. CVE-2022-24792)
- Potential heap buffer overflow when parsing DNS packets
(GHSA-p6g5-v97c-w5q4 a.k.a. CVE-2022-24793)
https://github.com/pjsip/pjproject/releases/tag/2.12.1
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>