Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-27599

Опубликовано: 15 мар. 2023
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.7 and 3.2.4, when the function append_hf handles a SIP message with a malformed To header, a call to the function abort() is performed, resulting in a crash. This is due to the following check in data_lump.c:399 in the function anchor_lump. An attacker abusing this vulnerability will crash OpenSIPS leading to Denial of Service. It affects configurations containing functions that make use of the affected code, such as the function append_hf. This issue has been fixed in versions 3.1.7 and 3.2.4.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:opensips:opensips:*:*:*:*:*:*:*:*
Версия до 3.1.7 (исключая)
cpe:2.3:a:opensips:opensips:*:*:*:*:*:*:*:*
Версия от 3.2.0 (включая) до 3.2.4 (исключая)

EPSS

Процентиль: 31%
0.00113
Низкий

7.5 High

CVSS3

Дефекты

CWE-20
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 3 года назад

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.7 and 3.2.4, when the function `append_hf` handles a SIP message with a malformed To header, a call to the function `abort()` is performed, resulting in a crash. This is due to the following check in `data_lump.c:399` in the function `anchor_lump`. An attacker abusing this vulnerability will crash OpenSIPS leading to Denial of Service. It affects configurations containing functions that make use of the affected code, such as the function `append_hf`. This issue has been fixed in versions 3.1.7 and 3.2.4.

EPSS

Процентиль: 31%
0.00113
Низкий

7.5 High

CVSS3

Дефекты

CWE-20
NVD-CWE-noinfo