Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-28097
HistoryMar 15, 2023 - 11:15 p.m.

Design/Logic Flaw

2023-03-1523:15:00
PRIOn knowledge base
www.prio-n.com
4
opensips
sip server
flaw
logic
content-length
segmentation fault
memory
version
nvd

0.001 Low

EPSS

Percentile

40.3%

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.9 and 3.2.6, a malformed SIP message containing a large Content-Length value and a specially crafted Request-URI causes a segmentation fault in OpenSIPS. This issue occurs when a large amount of shared memory using the -m flag was allocated to OpenSIPS, such as 10 GB of RAM. On the test system, this issue occurred when shared memory was set to 2362 or higher. This issue is fixed in versions 3.1.9 and 3.2.6. The only workaround is to guarantee that the Content-Length value of input messages is never larger than 2147483647.

CPENameOperatorVersion
opensipslt3.1.9
opensipsge3.2.0
opensipslt3.2.6

0.001 Low

EPSS

Percentile

40.3%

Related for PRION:CVE-2023-28097