pjsip 2.13 CVE patches can't be applied
There are 3 CVE fixed in pjsip 2.13, see https://github.com/pjsip/pjproject/releases/tag/2.13. I can't apply those patches. Could you please take a look? Thanks!
There are 3 CVE fixed in pjsip 2.13, see https://github.com/pjsip/pjproject/releases/tag/2.13. I can't apply those patches. Could you please take a look? Thanks!
Should be a direct apply, it's part we do not touch/modify
And I guess it's already applied, you opened a ticket some weeks ago about those CVE (#784 (closed) and daemon patch is https://review.jami.net/c/pjproject/+/22837 for CVE-2022-39244 and CVE-2022-39269)
Will check the third later.
I confirm the 3rd patch applies directly: https://review.jami.net/c/pjproject/+/23389 (patch -flp1 < cve-2022-31031.patch
).
assigned to @sblin
added security label
added sprintin progress label
added sprintto review label and removed sprintin progress label
mentioned in commit 5a30c3b8
removed sprintto review label
Applied on master (both daemon and our pjproject), will be available in next release/beta
closed