PT-2023-6421 · Sofia-Sip+3 · Sofia-Sip+3
Qiuhao Li
·
Published
2023-01-19
·
Updated
2025-08-12
·
CVE-2023-22741
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Sofia-SIP versions 1.12.4 and later, up to the version before the fix was introduced
Description
The issue is related to the lack of message length and attributes length checks when handling STUN packets, leading to a controllable heap-over-flow. This can be exploited by attackers to achieve remote code execution through heap grooming or other methods. The bug was introduced 16 years ago and users are advised to upgrade. There are no known workarounds for this vulnerability.
Recommendations
For Sofia-SIP versions 1.12.4 and later, up to the version before the fix was introduced:
Upgrade to a newer version to resolve the issue.
As a temporary workaround, consider restricting access to the
stun parse attribute() function until a patch is available.
Avoid using the length variable in the affected STUN packet handling code until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
RCE
Buffer Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Red Os
Sofia-Sip
Ubuntu