{"id":"openSUSE-SU-2024:0106-1","summary":"Security update for sngrep","details":"This update for sngrep fixes the following issues:\n\n- Update to version 1.8.1\n  * Fix CVE-2024-3119: sngrep: buffer overflow due to improper\n    handling of 'Call-ID' and 'X-Call-ID' SIP headers.\n  * Fix CVE-2024-3120: sngrep: stack-buffer overflow due to\n    inadequate bounds checking when copying 'Content-Length' and\n    'Warning' headers into fixed-size buffers.\n\n- Update to versino 1.8.0\n  * fix typo in message, thanks to lintian.\n  * fix compiler warnings about unused variables.\n  * Fixed a typo in comment line in filter.c\n  * Redefine usage of POSIX signals.\n  * Support for building sngrep using CMake added.\n\n- Update to version 1.7.0\n  * save: add option --text to save captured data to plain text\n  * capture: fix memory overflows while parsing IP headers\n  * hep: fix hep listener enabled in offline mode\n  * core: stop sngrep when parent process has ended\n  * ssl: fix decrypt with AES256 GCM SHA384 cipher\n","modified":"2026-03-11T07:33:32.242681Z","published":"2024-04-10T18:21:00Z","related":["CVE-2024-3119","CVE-2024-3120"],"upstream":["CVE-2024-3119","CVE-2024-3120"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XIKQJYLNI5D5D5THR2I23E2KMGZKXH46/"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-3119"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-3120"}],"affected":[{"package":{"name":"sngrep","ecosystem":"SUSE:Package Hub 15 SP5","purl":"pkg:rpm/suse/sngrep&distro=SUSE%20Package%20Hub%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.8.1-bp155.2.3.1"}]}],"ecosystem_specific":{"binaries":[{"sngrep":"1.8.1-bp155.2.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2024:0106-1.json"}},{"package":{"name":"sngrep","ecosystem":"openSUSE:Leap 15.5","purl":"pkg:rpm/opensuse/sngrep&distro=openSUSE%20Leap%2015.5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.8.1-bp155.2.3.1"}]}],"ecosystem_specific":{"binaries":[{"sngrep":"1.8.1-bp155.2.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2024:0106-1.json"}}],"schema_version":"1.7.5"}