PT-2006-7472 · Openser · Openser

Published

2006-12-31

·

Updated

2018-10-17

·

CVE-2006-6875

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: OpenSER versions 1.1.0 and earlier
Description: The issue is related to a buffer overflow in the validateospheader function within the Open Settlement Protocol (OSP) module. This allows remote attackers to execute arbitrary code by sending a crafted OSP header.
Recommendations: For OpenSER versions 1.1.0 and earlier, consider disabling the OSP module until a patch is available. Restrict access to the validateospheader function to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-6875

Affected Products

Openser