7.5
CVSSv2

CVE-2018-8828

Published: 20/03/2018 Updated: 24/08/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

A Buffer Overflow issue exists in Kamailio prior to 4.4.7, 5.0.x prior to 5.0.6, and 5.1.x prior to 5.1.2. A specially crafted REGISTER message with a malformed branch or From tag triggers an off-by-one heap-based buffer overflow in the tmx_check_pretran function in modules/tmx/tmx_pretran.c.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

kamailio kamailio

debian debian linux 9.0

debian debian linux 8.0

Vendor Advisories

kamailio could be made to crash if it opened a specially crafted file ...
Alfred Farrugia and Sandro Gauci discovered an off-by-one heap overflow in the Kamailio SIP server which could result in denial of service and potentially the execution of arbitrary code For the oldstable distribution (jessie), this problem has been fixed in version 420-2+deb8u3 For the stable distribution (stretch), this problem has been fixed ...