PT-2015-7546 · Signalwire+1 · Freeswitch+1

Published

2015-10-05

·

Updated

2018-10-09

·

CVE-2015-7392

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions FreeSWITCH versions prior to 1.4.23 FreeSWITCH versions 1.6.x prior to 1.6.2
Description The issue is related to a heap-based buffer overflow in the parse string function, located in libs/esl/src/esl json.c. This allows remote attackers to execute arbitrary code by sending a specially crafted JSON string containing a trailing u to the cJSON Parse function.
Recommendations For FreeSWITCH versions prior to 1.4.23, update to version 1.4.23 or later. For FreeSWITCH versions 1.6.x prior to 1.6.2, update to version 1.6.2 or later.

Exploit

Fix

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1882
CVE-2015-7392

Affected Products

Alt Linux
Freeswitch