{
  "schema_version": "1.7.0",
  "id": "MGASA-2013-0279",
  "published": "2013-09-19T09:32:15Z",
  "modified": "2013-09-19T09:32:06Z",
  "summary": "Updated freeswitch packages fix security vulnerability",
  "details": "In FreeSWITCH before 1.2.12, if the routing configuration includes\nregular expressions that don't constrain the length of the input, buffer\noverflows are possible. Since these regular expressions are matched\nagainst untrusted input, remote code execution may be possible\n(CVE-2013-2238).\n",
  "upstream": [
    "CVE-2013-2238"
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://advisories.mageia.org/MGASA-2013-0279.html"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.mageia.org/show_bug.cgi?id=10743"
    },
    {
      "type": "WEB",
      "url": "http://openwall.com/lists/oss-security/2013/07/01/11"
    },
    {
      "type": "WEB",
      "url": "http://jira.freeswitch.org/browse/FS-5566"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "Mageia:3",
        "name": "freeswitch",
        "purl": "pkg:rpm/mageia/freeswitch?arch=source&distro=mageia-3"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "1.2.12-6.mga3"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    }
  ],
  "credits": [
    {
      "name": "Mageia",
      "type": "COORDINATOR",
      "contact": [
        "https://wiki.mageia.org/en/Packages_Security_Team"
      ]
    }
  ]
}
