PT-2022-20450 · Sofia-Sip+4 · Sofia-Sip+4

Cossack9989

·

Published

2022-05-31

·

Updated

2025-08-12

·

CVE-2022-31003

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Sofia-SIP versions prior to 1.13.8
Description Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. When parsing each line of a sdp message, rest = record + 2 will access the memory behind 0 and cause an out-of-bounds write. An attacker can send a message with evil sdp to FreeSWITCH, causing a crash or more serious consequence, such as remote code execution.
Recommendations For versions prior to 1.13.8, update to version 1.13.8 to resolve the issue. As a temporary workaround, consider restricting the parsing of sdp messages to prevent potential crashes or remote code execution. Avoid using the vulnerable rest = record + 2 line in the sdp message parsing function until the issue is resolved.

Exploit

Fix

RCE

Memory Corruption

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-09870
CVE-2022-31003
DLA-3091-1
DSA-5410-1
GHSA-8W5J-6G2J-PXCP
MGASA-2022-0343
USN-5932-1

Affected Products

Freeswitch
Linuxmint
Red Os
Sofia-Sip
Ubuntu