PT-2023-6421 · Sofia-Sip+3 · Sofia-Sip+3

Qiuhao Li

·

Published

2023-01-19

·

Updated

2025-08-12

·

CVE-2023-22741

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Sofia-SIP versions 1.12.4 and later, up to the version before the fix was introduced
Description The issue is related to the lack of message length and attributes length checks when handling STUN packets, leading to a controllable heap-over-flow. This can be exploited by attackers to achieve remote code execution through heap grooming or other methods. The bug was introduced 16 years ago and users are advised to upgrade. There are no known workarounds for this vulnerability.
Recommendations For Sofia-SIP versions 1.12.4 and later, up to the version before the fix was introduced: Upgrade to a newer version to resolve the issue. As a temporary workaround, consider restricting access to the stun parse attribute() function until a patch is available. Avoid using the length variable in the affected STUN packet handling code until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Buffer Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2023-07137
CVE-2023-22741
DLA-3292-1
DSA-5410-1
GHSA-8599-X7RQ-FR54
MGASA-2023-0040
USN-5932-1

Affected Products

Linuxmint
Red Os
Sofia-Sip
Ubuntu