PT-2023-11761 · Unknown+2 · Kamailio Sip+2

Rnatella

·

Published

2023-03-15

·

Updated

2025-02-27

·

CVE-2020-27507

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kamailio SIP versions prior to 5.5.0
Description The issue is related to the mishandling of INVITE requests with duplicated fields and overlength tags by the Kamailio SIP server, leading to a buffer overflow. This can cause the server to crash or potentially have other unspecified impacts.
Recommendations For versions prior to 5.5.0, update to version 5.5.0 or later to resolve the issue. As a temporary workaround, consider restricting access to INVITE requests with duplicated fields and overlength tags until a patch is applied.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2020-27507
DLA-3438-1
USN-6022-1

Affected Products

Kamailio Sip
Linuxmint
Ubuntu