PT-2023-21237 · Opensips · Opensis

Alfredfarrugia

+1

·

Publicado

2023-03-15

·

Atualizado

2023-03-21

·

CVE-2023-27597

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenSIPS versions prior to 3.1.8 and 3.2.5
Description OpenSIPS is a Session Initiation Protocol (SIP) server implementation. When a specially crafted SIP message is processed by the function rewrite ruri, a crash occurs due to a segmentation fault, causing the server to crash. This issue affects configurations containing functions that make use of the affected code, such as the function setport.
Recommendations For versions prior to 3.1.8, update to version 3.1.8 or later. For versions prior to 3.2.5, update to version 3.2.5 or later. As a temporary workaround, consider disabling the rewrite ruri function until a patch is available. Restrict access to configurations containing functions that make use of the affected code, such as the function setport, to minimize the risk of exploitation.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-27597
GHSA-358F-935M-7P9C

Produtos afetados

Opensis