#RTPEngine
I say it monthly... "There are those who read what @sandrogauci.bsky.social and @enablesecurity.bsky.social write... and those who wish they had."

Big items in this month's newsletter.

www.enablesecurity.com/newsletter/2...

#sip #voip #rtp
July 2025: Rtpengine fixes, RTC conferences and showers of vulnerabilities
July 2025 RTCSec newsletter: Rtpengine fixes, RTC conferences and showers of vulnerabilities
www.enablesecurity.com
July 31, 2025 at 6:32 PM
Amazing!!!

I've been debugging an issue for a couple hours and finally got some clean logs, but RTPEngine logs are absolutely MASSIVE. Super hard to look through manually.

Gemini nailed it.

Btw, I tried this same exact query with ChatGPT and it didn't work nearly as well.
December 11, 2024 at 8:02 PM
Happy to announce that I just released updated Ubuntu 24.04 LTS packages for Kamailio, rtpengine and FreeSWITCH for anyone to use. You can use Docker to build the packages yourself.

github.com/ProVoice/pro...
github.com/ProVoice/pro...
github.com/ProVoice/pro...
Releases · ProVoice/provoice-build-kamailio
ProVoice packages build environment for Kamailio using Docker - ProVoice/provoice-build-kamailio
github.com
November 17, 2024 at 10:43 AM
We’ve just completed the rollout of our updated transcoding layer using RTPEngine. 🎉 With a few targeted changes, we’re now prioritising the OPUS codec - and the improvement in call quality has been immediately noticeable! #WebRTC #Siperb #Softphone #OpenSIPS #RTPEngine #OpusCodec
April 19, 2026 at 2:08 PM
⏳ EOL radar · Sep 11

🔴 rtpengine 11.5 reaches end of life TODAY
https://endoflife.ai/rtpengine

🟠 BellSoft Liberica 26: 7 days to end of life
https://endoflife.ai/bellsoft-liberica

🟠 OpenJDK builds from Oracle 26: 7 days to end of life
https://endoflife.ai/openjdk-builds-from-oracle
September 11, 2026 at 6:11 PM
⏳ EOL radar · Sep 10

🔴 rtpengine 11.5: end of life TOMORROW
https://endoflife.ai/rtpengine

🟠 GitLab 19.1: 7 days to end of life
https://endoflife.ai/gitlab

🟠 GitLab Runner 19.1: 7 days to end of life
https://endoflife.ai/gitlab-runner
September 10, 2026 at 6:08 PM
Good read: "What to expect from Debian / trixie"

For VoIP people...

Included:

Kamailio (6.0.1)
RTPengine (12.5.1)

michael-prokop.at/blog/2025/07...
mikas blog » Blog Archive » What to expect from Debian/trixie #newintrixie
michael-prokop.at
July 24, 2025 at 6:49 PM
Critical Rtpengine Flaws (CVE-2025-53399) Allow Audio Interception and Injection in VoIP Calls, PoC Publishes
Critical Rtpengine Flaws (CVE-2025-53399) Allow Audio Interception and Injection in VoIP Calls, PoC Publishes
Rtpengine's critical flaws (CVE-2025-53399, CVSS 9.3) allow attackers to intercept or inject audio into active VoIP calls, even without a MitM position, by exploiting SRTP validation.
securityonline.info
July 31, 2025 at 4:09 PM
Rtpengine: RTP Inject and RTP Bleed vulnerabilities despite proper configuration (CVSS v4.0 Score: 9.3 / Critical)

Posted by Sandro Gauci via Fulldisclosure on Aug 02Rtpengine: RTP Inject and RTP Bleed vulnerabilities despite proper configuration (CVSS v4.0 Score: 9.3 / Critical…

#hackernews #news
Rtpengine: RTP Inject and RTP Bleed vulnerabilities despite proper configuration (CVSS v4.0 Score: 9.3 / Critical)
Posted by Sandro Gauci via Fulldisclosure on Aug 02Rtpengine: RTP Inject and RTP Bleed vulnerabilities despite proper configuration (CVSS v4.0 Score: 9.3 / Critical) - CVSS v4.0 - Exploitability: High - Complexity: Low - Vulnerable system: Medium - Subsequent system: Medium - Exploitation: High - Security requirements: High - Vector: https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:H/SI:H/SA:H - Other references:...
seclists.org
August 4, 2025 at 6:09 AM
Rtpengine mr13.4.1.1 Injection / Redirection https://packetstorm.news/files/207715 #exploit
July 31, 2025 at 7:48 PM
RTPengine’s Comedy of Errors: Bleeding Vulnerabilities Despite Best Intentions!

RTPengine vulnerabilities: RTP Inject & RTP Bleed can lead to critical exploits despite proper configuration. Update to version mr13.4.1.1 for security fixes!
thenimblenerd.com?p=1052092
RTPengine’s Comedy of Errors: Bleeding Vulnerabilities Despite Best Intentions!
Rtpengine vulnerabilities "RTP Inject" and "RTP Bleed" persist despite proper configuration, with a CVSS 4.0 score of 9.3 (critical). These attacks don't require the attacker as a middleman, and SRTP doesn't always prevent them. Thankfully, updates in version mr13.4.1.1 aim to patch these security holes, giving hackers a run for their RTP.
thenimblenerd.com
August 3, 2025 at 3:12 AM
Now "Enabling AI-Powered Conversations at Scale with #Kamailio, FreeSwitch, and RTPEngine" at @fosdem'25 #RTCDevroom: fosdem.org/2025/schedul...
February 1, 2025 at 2:42 PM
For those who might have missed it or if you just want to review it again, I'm happy to share with you all, the video for my talk: 'Enabling AI-Powered Conversations at Scale with Kamailio, FreeSwitch, and RTPEngine' at this Year's FOSDEM. 👉 […]
Original post on fosstodon.org
fosstodon.org
February 13, 2025 at 12:07 AM