[kamailio/kamailio] Core: TCP Vulnerability (GHSA-2wj4-f825-2h2f)
### Impact Within a specific type of Kamailio deployment / configuration, a specially crafted data packet sent over TCP can trigger a crash in Kamailio. An out-of-bounds access in the core of Kamailio (formerly OpenSER and SER) before the versions 6.1.1, 6.0.6, or 5.8.8 allows remote attackers to cause a denial of service (process crash) via a specially crafted data packet sent over TCP. The issue impacts Kamailio instances having TCP or TLS listeners. ### Patches The issue is patched in: - 6.1.1 - 6.0.6 - 5.8.8 ### Workarounds Older instances are recommended to update to the above supported systems. The latest two stable branches are supported. Older versions may get patches from time to time (e.g., 5.8/7), but you have to maintain the installation from git repository, because packages are built only for last two stable branches. -- Reply to this email directly or view it on GitHub: https://github.com/kamailio/kamailio/security/advisories/GHSA-2wj4-f825-2h2f You are receiving this because you are an administrator on kamailio/kamailio. Message ID: <kamailio/kamailio/repository-advisories/GHSA-2wj4-f825-2h2f@github.com>
Can we point out the commits when this was introduced? -- Reply to this email directly or view it on GitHub: https://github.com/kamailio/kamailio/security/advisories/GHSA-2wj4-f825-2h2f... You are receiving this because you are either an administrator on kamailio/kamailio, or a collaborator on GHSA-2wj4-f825-2h2f. Message ID: <kamailio/kamailio/repository-advisories/454601/comments/185008@github.com>
Published GHSA-2wj4-f825-2h2f. -- Reply to this email directly or view it on GitHub: https://github.com/kamailio/kamailio/security/advisories/GHSA-2wj4-f825-2h2f... You are receiving this because you are either an administrator on kamailio/kamailio, or a collaborator on GHSA-2wj4-f825-2h2f. Message ID: <kamailio/kamailio/repository-advisories/454601/events/619137@github.com>
participants (2)
-
Fred Posner -
Olle E. Johansson