Alpine: multiple freeswitch packages: security update to 1.10.11-r0

medium Tenable Cloud Security Plugin ID 423911

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary
telecom switches to a software implementation that runs on any commodity hardware. Prior to version
1.10.11, when handling DTLS-SRTP for media setup, FreeSWITCH is susceptible to Denial of Service due to a
race condition in the hello handshake phase of the DTLS protocol. This attack can be done continuously,
thus denying new DTLS-SRTP encrypted calls during the attack. If an attacker manages to send a ClientHello
DTLS message with an invalid CipherSuite (such as `TLS_NULL_WITH_NULL_NULL`) to the port on the FreeSWITCH
server that is expecting packets from the caller, a DTLS error is generated. This results in the media
session being torn down, which is followed by teardown at signaling (SIP) level too. Abuse of this
vulnerability may lead to a massive Denial of Service on vulnerable FreeSWITCH servers for calls that rely
on DTLS-SRTP. To address this vulnerability, upgrade FreeSWITCH to 1.10.11 which includes the security
fix. The solution implemented is to drop all packets from addresses that have not been validated by an ICE
check. (CVE-2023-51443)

See Also

https://security.alpinelinux.org/vuln/CVE-2023-51443

Plugin Details

Severity: Medium

ID: 423911

Version: Revision 1.8

Type: Local

Published: 4/4/2025

Updated: 7/2/2026

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

CVSS v2

Risk Factor: Medium

Base Score: 5.4

Temporal Score: 4.2

Vector: CVSS2#AV:N/AC:H/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2023-51443

CVSS v3

Risk Factor: Medium

Base Score: 5.9

Temporal Score: 5.3

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 12/27/2023

Reference Information

CVE: CVE-2023-51443