All errata/sisyphus/ALT-PU-2015-1882-1
ALT-PU-2015-1882-1

Package update freeswitch in branch sisyphus

Version1.4.23-alt1
Published2015-10-17
Max severityHIGH
Severity:

Closed issues (1)

CVE-2015-7392
HIGH7.5

Heap-based buffer overflow in the parse_string function in libs/esl/src/esl_json.c in FreeSWITCH before 1.4.23 and 1.6.x before 1.6.2 allows remote attackers to execute arbitrary code via a trailing \u in a json string to cJSON_Parse.

Published: 2015-10-05Modified: 2025-04-12
CVSS 2.0HIGH 7.5
CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:P