The Kamailio SIP before 5.5.0 server mishandles INVITE requests with duplicated fields and overlength tag, leading to a buffer overflow that crashes the server or possibly have unspecified other impact.
References
Link | Resource |
---|---|
https://github.com/kamailio/kamailio/commit/ada3701d22b1fd579f06b4f54fa695fa988e685f | Patch |
https://github.com/kamailio/kamailio/issues/2503 | Exploit Issue Tracking |
Configurations
Information
Published : 2023-03-15 13:15
Updated : 2023-03-18 20:50
NVD link : CVE-2020-27507
Mitre link : CVE-2020-27507
JSON object : View
CWE
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Products Affected
kamailio
- kamailio