PT-2023-21237 · Opensips · Opensis

Alfredfarrugia

+1

·

Published

2023-03-15

·

Updated

2023-03-21

·

CVE-2023-27597

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenSIPS versions prior to 3.1.8 and 3.2.5
Description OpenSIPS is a Session Initiation Protocol (SIP) server implementation. When a specially crafted SIP message is processed by the function rewrite ruri, a crash occurs due to a segmentation fault, causing the server to crash. This issue affects configurations containing functions that make use of the affected code, such as the function setport.
Recommendations For versions prior to 3.1.8, update to version 3.1.8 or later. For versions prior to 3.2.5, update to version 3.2.5 or later. As a temporary workaround, consider disabling the rewrite ruri function until a patch is available. Restrict access to configurations containing functions that make use of the affected code, such as the function setport, to minimize the risk of exploitation.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2023-27597
GHSA-358F-935M-7P9C

Affected Products

Opensis