DSA-4267-1 kamailio -- security update

Related Vulnerabilities: CVE-2018-14767  

Henning Westerholt discovered a flaw related to the To header processing in kamailio, a very fast, dynamic and configurable SIP server. Missing input validation in the build_res_buf_from_sip_req function could result in denial of service and potentially the execution of arbitrary code. For the stable distribution (stretch), this problem has been fixed in version 4.4.4-2+deb9u2. We recommend that you upgrade your kamailio packages. For the detailed security status of kamailio please refer to its security tracker page at: https://security-tracker.debian.org/tracker/kamailio

Debian Security Advisory

DSA-4267-1 kamailio -- security update

Date Reported:
08 Aug 2018
Affected Packages:
kamailio
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2018-14767.
More information:

Henning Westerholt discovered a flaw related to the To header processing in kamailio, a very fast, dynamic and configurable SIP server. Missing input validation in the build_res_buf_from_sip_req function could result in denial of service and potentially the execution of arbitrary code.

For the stable distribution (stretch), this problem has been fixed in version 4.4.4-2+deb9u2.

We recommend that you upgrade your kamailio packages.

For the detailed security status of kamailio please refer to its security tracker page at: https://security-tracker.debian.org/tracker/kamailio