The Kamailio SIP before 5.5.0 server mishandles INVITE...
Critical severity
Unreviewed
Published
Mar 15, 2023
to the GitHub Advisory Database
•
Updated Jun 8, 2023
Description
Published by the National Vulnerability Database
Mar 15, 2023
Published to the GitHub Advisory Database
Mar 15, 2023
Last updated
Jun 8, 2023
The Kamailio SIP before 5.5.0 server mishandles INVITE requests with duplicated fields and overlength tag, leading to a buffer overflow that crashes the server or possibly have unspecified other impact.
References