CVE-2018-14767
31.07.2018, 06:29
In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with a double "To" header and an empty "To" tag causes a segmentation fault and crash. The reason is missing input validation in the "build_res_buf_from_sip_req" core function. This could result in denial of service and potentially the execution of arbitrary code.Enginsight
Vendor | Product | Version |
---|---|---|
debian | debian_linux | 8.0 |
debian | debian_linux | 9.0 |
kamailio | kamailio | 𝑥 < 5.0.7 |
kamailio | kamailio | 5.1.0 ≤ 𝑥 < 5.1.4 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References