PT-2018-12707 · Kamailio+2 · Kamailio+2
Henning Westerholt
·
Publicado
2018-07-31
·
Atualizado
2025-04-07
·
CVE-2018-14767
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Kamailio versions prior to 5.0.7
Kamailio versions 5.1.x prior to 5.1.4
Description
A crafted SIP message with a double "To" header and an empty "To" tag can cause a segmentation fault and crash due to missing input validation in the
build res buf from sip req core function. This could result in denial of service and potentially the execution of arbitrary code.Recommendations
For Kamailio versions prior to 5.0.7, update to version 5.0.7 or later.
For Kamailio versions 5.1.x prior to 5.1.4, update to version 5.1.4 or later.
As a temporary workaround, consider implementing additional input validation for SIP messages to prevent crashes.
Exploit
Correção
DoS
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Kamailio
Linuxmint
Ubuntu