PT-2023-21555 · Opensips · Opensis

Alfred Farrugia

+1

·

Published

2023-03-15

·

Updated

2023-03-21

·

CVE-2023-28095

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenSIPS versions prior to 3.1.7 OpenSIPS versions prior to 3.2.4
Description OpenSIPS is a Session Initiation Protocol (SIP) server implementation. The issue is located in msg translator.c:2628 and might lead to a server crash. This issue was found while fuzzing the function build res buf from sip req but could not be reproduced against a running instance of OpenSIPS. It is highly unlikely that this issue would lead to anything other than Denial of Service, even in the case of exploitation through unknown vectors.
Recommendations For versions prior to 3.1.7, update to version 3.1.7 or later. For versions prior to 3.2.4, update to version 3.2.4 or later.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2023-28095
GHSA-7PF3-24QG-8V9H

Affected Products

Opensis