- ------------------------------------------------------------------------- Debian LTS Advisory DLA-3438-1 [email protected] https://www.debian.org/lts/security/ Chris Lamb May 30, 2023 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : kamailio Version : 5.2.1-1+deb10u1 CVE ID : CVE-2020-27507 It was discovered that there was a potential denial-of-service (DoS) attack in the Kamailio SIP telephony server. This was caused by the Kamailio server mishandling INVITE requests with duplicated fields. For Debian 10 buster, this problem has been fixed in version 5.2.1-1+deb10u1. We recommend that you upgrade your kamailio packages. For the detailed security status of kamailio please refer to its security tracker page at: https://security-tracker.debian.org/tracker/kamailio Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS