PT-2022-20448 · Sofia-Sip+5 · Sofia-Sip+5

Cossack9989

·

Published

2022-05-31

·

Updated

2025-08-12

·

CVE-2022-31001

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Sofia-SIP versions prior to 1.13.8
Description Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. An attacker can send a message with malicious sdp to FreeSWITCH, which may cause a crash. This type of crash may be caused by #define MATCH(s, m) (strncmp(s, m, n = sizeof(m) - 1) == 0), which will make n bigger and trigger out-of-bound access when IS NON WS(s[n]).
Recommendations For versions prior to 1.13.8, update to version 1.13.8 to resolve the issue. As a temporary workaround, consider restricting the handling of sdp messages from untrusted sources until the patch is applied.

Exploit

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2574
ALT-PU-2022-2598
ALT-PU-2023-5729
BDU:2025-09864
CVE-2022-31001
DLA-3091-1
DSA-5410-1
GHSA-79JQ-HH82-CV9G
MGASA-2022-0343
USN-5932-1

Affected Products

Alt Linux
Freeswitch
Linuxmint
Red Os
Sofia-Sip
Ubuntu