Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-27596
HistoryMar 15, 2023 - 12:00 a.m.

CVE-2023-27596

2023-03-1500:00:00
ubuntu.com
ubuntu.com
18
opensips
sip server
vulnerability
sdp body
configuration
crash
function
codecs
unix

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

38.4%

OpenSIPS is a Session Initiation Protocol (SIP) server implementation.
Prior to versions 3.1.8 and 3.2.5, OpenSIPS crashes when a malformed SDP
body is sent multiple times to an OpenSIPS configuration that makes use of
the stream_process function. This issue was discovered during coverage
guided fuzzing of the function codec_delete_except_re. By abusing this
vulnerability, an attacker is able to crash the server. It affects
configurations containing functions that rely on the affected code, such as
the function codec_delete_except_re. This issue has been fixed in version
3.1.8 and 3.2.5.

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchopensips< anyUNKNOWN

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

38.4%

Related for UB:CVE-2023-27596