PT-2018-18648 · Kamailio+1 · Kamailio+1

Alfred Farrugia

+1

·

Published

2018-03-20

·

Updated

2020-08-24

·

CVE-2018-8828

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kamailio versions prior to 4.4.7 Kamailio versions 5.0.x prior to 5.0.6 Kamailio versions 5.1.x prior to 5.1.2
Description A Buffer Overflow issue was discovered. A specially crafted REGISTER message with a malformed branch or From tag triggers an off-by-one heap-based buffer overflow in the tmx check pretran function.
Recommendations For versions prior to 4.4.7, update to version 4.4.7 or later. For versions 5.0.x prior to 5.0.6, update to version 5.0.6 or later. For versions 5.1.x prior to 5.1.2, update to version 5.1.2 or later.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-8828
DSA-4148-1
USN-4240-1

Affected Products

Kamailio
Ubuntu