PT-2015-7546 · Signalwire+1 · Freeswitch+1

Publicado

2015-10-05

·

Atualizado

2018-10-09

·

CVE-2015-7392

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions FreeSWITCH versions prior to 1.4.23 FreeSWITCH versions 1.6.x prior to 1.6.2
Description The issue is related to a heap-based buffer overflow in the parse string function, located in libs/esl/src/esl json.c. This allows remote attackers to execute arbitrary code by sending a specially crafted JSON string containing a trailing u to the cJSON Parse function.
Recommendations For FreeSWITCH versions prior to 1.4.23, update to version 1.4.23 or later. For FreeSWITCH versions 1.6.x prior to 1.6.2, update to version 1.6.2 or later.

Exploit

Correção

RCE

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-1882
CVE-2015-7392

Produtos afetados

Alt Linux
Freeswitch