Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

Debian DSA-4148-1: Kamailio Heap Overflow Denial Of Service Threat

debian
Calendar Grey March 22, 2018
Debian Logo
Explore the risks associated with a denial of service vulnerability stemming from an off-by-one buffer overflow in Kamailio. Debian users are advised to perform an upgrade.
Alfred Farrugia and Sandro Gauci discovered an off-by-one heap overflow in the Kamailio SIP server which could result in denial of service and potentially the execution of arbitrar...

Summary

Alfred Farrugia and Sandro Gauci discovered an off-by-one heap overflow
in the Kamailio SIP server which could result in denial of service and
potentially the execution of arbitrary code.

For the oldstable distribution (jessie), this problem has been fixed
in version 4.2.0-2+deb8u3.

For the stable distribution (stretch), this problem has been fixed in
version 4.4.4-2+deb9u1.

We recommend that you upgrade your kamailio packages.

For the detailed security status of kamailio please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/kamailio

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: kamailio
CVE ID: CVE-2018-8828

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here