{"id":13061,"date":"2022-03-02T18:36:40","date_gmt":"2022-03-02T20:36:40","guid":{"rendered":"https:\/\/teknomers.com\/fr\/bogues-critiques-signales-dans-le-populaire-sip-pjsip-open-source-et-media-stack\/"},"modified":"2022-03-02T18:36:57","modified_gmt":"2022-03-02T20:36:57","slug":"bogues-critiques-signales-dans-le-populaire-sip-pjsip-open-source-et-media-stack","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/bogues-critiques-signales-dans-le-populaire-sip-pjsip-open-source-et-media-stack\/","title":{"rendered":"Bogues critiques signal\u00e9s dans le populaire SIP PJSIP Open Source et Media Stack"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both\"><\/div>\n<p>Jusqu&#8217;\u00e0 cinq vuln\u00e9rabilit\u00e9s de s\u00e9curit\u00e9 ont \u00e9t\u00e9 r\u00e9v\u00e9l\u00e9es dans la biblioth\u00e8que de communication multim\u00e9dia open source PJSIP qui pourraient \u00eatre exploit\u00e9es par un attaquant pour d\u00e9clencher l&#8217;ex\u00e9cution de code arbitraire et le d\u00e9ni de service (DoS) dans les applications qui utilisent la pile de protocoles.<\/p>\n<p>Les faiblesses \u00e9taient <a rel=\"nofollow noopener\" href=\"https:\/\/jfrog.com\/blog\/jfrog-discloses-5-memory-corruption-vulnerabilities-in-pjsip-a-popular-multimedia-library\/\" target=\"_blank\">identifi\u00e9 et d\u00e9clar\u00e9<\/a> par l&#8217;\u00e9quipe de recherche en s\u00e9curit\u00e9 de JFrog, apr\u00e8s quoi les responsables du projet ont publi\u00e9 des correctifs (<a rel=\"nofollow noopener\" href=\"https:\/\/github.com\/pjsip\/pjproject\/releases\/tag\/2.12\" target=\"_blank\">version 2.12<\/a>) la semaine derni\u00e8re, le 24 f\u00e9vrier 2022.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/mset1\" target=\"_blank\" title=\"Automatic GitHub Backups\"><img loading=\"lazy\" decoding=\"async\" alt=\"Sauvegardes GitHub automatiques\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/02\/TrickBot-Gang-est-susceptible-de-modifier-ses-operations-pour-passer.png\" width=\"300\" height=\"250\" \/><\/a><\/div>\n<p>PJSIP est un logiciel embarqu\u00e9 open-source <a rel=\"nofollow noopener\" href=\"https:\/\/en.wikipedia.org\/wiki\/Session_Initiation_Protocol\" target=\"_blank\">Protocole SIP<\/a> suite \u00e9crite en C qui prend en charge les fonctionnalit\u00e9s audio, vid\u00e9o et de messagerie instantan\u00e9e pour les plates-formes de communication populaires telles que <a rel=\"nofollow noopener\" href=\"https:\/\/googleprojectzero.blogspot.com\/2018\/12\/adventures-in-video-conferencing-part-3.html\" target=\"_blank\">Whatsapp<\/a> et BlueJeans.  C&#8217;est aussi <a rel=\"nofollow noopener\" href=\"https:\/\/wiki.asterisk.org\/wiki\/display\/AST\/PJSIP-pjproject\" target=\"_blank\">utilis\u00e9<\/a> par Asterisk, un syst\u00e8me de commutation d&#8217;autocommutateur priv\u00e9 (PBX) largement utilis\u00e9 pour les r\u00e9seaux VoIP.<\/p>\n<p>&#8220;Les tampons utilis\u00e9s dans PJSIP ont g\u00e9n\u00e9ralement des tailles limit\u00e9es, en particulier celles allou\u00e9es dans la pile ou fournies par l&#8217;application, mais \u00e0 plusieurs endroits, nous ne v\u00e9rifions pas si notre utilisation peut d\u00e9passer les tailles&#8221;, a d\u00e9clar\u00e9 Sauw Ming, d\u00e9veloppeur de PJSIP. <a rel=\"nofollow noopener\" href=\"https:\/\/github.com\/pjsip\/pjproject\/security\/advisories\/GHSA-qcvw-h34v-c7r9\" target=\"_blank\">c&#8217;est not\u00e9<\/a> dans un avis publi\u00e9 sur GitHub le mois dernier, un sc\u00e9nario qui pourrait entra\u00eener des d\u00e9bordements de tampon.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/cs-jan-webinar-inside\" target=\"_blank\" title=\"Prevent Data Breaches\"><img loading=\"lazy\" decoding=\"async\" alt=\"Emp\u00eacher les violations de donn\u00e9es\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/02\/1645701002_140_Dridex-Malware-Deploiement-Entropy-Ransomware-sur-des-ordinateurs-pirates.png\" width=\"728\" height=\"90\" \/><\/a><\/div>\n<p>La liste des d\u00e9fauts est la suivante \u2013<\/p>\n<ul>\n<li><strong>CVE-2021-43299<\/strong> (Score CVSS\u00a0: 8,1) &#8211; D\u00e9bordement de pile dans l&#8217;API PJSUA lors de l&#8217;appel de pjsua_player_create()<\/li>\n<li><strong>CVE-2021-43300<\/strong> (Score CVSS\u00a0: 8,1) &#8211; D\u00e9bordement de pile dans l&#8217;API PJSUA lors de l&#8217;appel de pjsua_recorder_create()<\/li>\n<li><strong>CVE-2021-43301<\/strong> (Score CVSS\u00a0: 8,1) &#8211; D\u00e9bordement de pile dans l&#8217;API PJSUA lors de l&#8217;appel de pjsua_playlist_create()<\/li>\n<li><strong>CVE-2021-43302<\/strong> (Score CVSS\u00a0: 5,9) &#8211; Lecture hors limites dans l&#8217;API PJSUA lors de l&#8217;appel de pjsua_recorder_create()<\/li>\n<li><strong>CVE-2021-43303<\/strong> (Score CVSS\u00a0: 5,9) &#8211; D\u00e9bordement de tampon dans l&#8217;API PJSUA lors de l&#8217;appel de pjsua_call_dump()<\/li>\n<\/ul>\n<p>L&#8217;exploitation r\u00e9ussie des failles susmentionn\u00e9es pourrait permettre \u00e0 un acteur malveillant de transmettre des arguments contr\u00f4l\u00e9s par l&#8217;attaquant \u00e0 l&#8217;une des API vuln\u00e9rables, conduisant \u00e0 l&#8217;ex\u00e9cution de code et \u00e0 une condition DoS, a d\u00e9clar\u00e9 Uriya Yavnieli, chercheur JFrog qui a signal\u00e9 les failles.<\/p>\n<p><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2022\/03\/critical-bugs-reported-in-popular-open.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Jusqu&#8217;\u00e0 cinq vuln\u00e9rabilit\u00e9s de s\u00e9curit\u00e9 ont \u00e9t\u00e9 r\u00e9v\u00e9l\u00e9es dans la biblioth\u00e8que de communication multim\u00e9dia open source PJSIP qui pourraient \u00eatre exploit\u00e9es par un attaquant pour d\u00e9clencher l&#8217;ex\u00e9cution de code arbitraire et le d\u00e9ni de service (DoS) dans les applications qui utilisent la pile de protocoles. Les faiblesses \u00e9taient identifi\u00e9 et d\u00e9clar\u00e9 par l&#8217;\u00e9quipe de recherche [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":13062,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[14862,4168,5729,4158,4165,4161,429,4157,4159,4171,4170,4167,14866,4160,4163,4162,14531,14865,440,4172,4169,14863,14864,11137,14867,4166,4164],"class_list":["post-13061","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-bogues","tag-comment-pirater","tag-critiques","tag-cyber-actualites","tag-cyber-attaques","tag-cyber-mises-a-jour","tag-dans","tag-lactualite-de-la-cybersecurite","tag-lactualite-de-la-cybersecurite-aujourdhui","tag-lactualite-des-hackers","tag-la-securite-des-informations","tag-logiciel-malveillant-de-ransomware","tag-media","tag-mises-a-jour-de-la-cybersecurite","tag-nouvelles-de-piratage","tag-nouvelles-de-pirates","tag-open","tag-pjsip","tag-populaire","tag-securite-informatique","tag-securite-internet","tag-signales","tag-sip","tag-source","tag-stack","tag-violation-de-donnees","tag-vulnerabilite-logicielle"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/13061","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=13061"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/13061\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/13062"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=13061"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=13061"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=13061"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}