Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 1 articles for you...
172

Ubuntu 20.04: USN-7416-1 moderate: Kamailio Memory Issues

Several security issues were fixed in Kamailio.. ========================================================================== Ubuntu Security Notice USN-7416-1 April 07, 2025 kamailio vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in Kamailio. Software Description: - kamailio: very fast, dynamic and configurable SIP server Details: Stelios Tsampas discovered that Kamailio did not correctly handle certain memory operations, which could lead to a buffer overflow. A remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-2385) Henning Westerholt discovered that Kamailio did not correctly handle duplicated headers, which could lead to a segmentation fault. A remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2018-14767) It was discovered that Kamailio did not correctly handle parsing certain headers containing whitespace characters. An authenticated attacker could possibly use this issue to gain access to unauthorized resources and expose sensitive information. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-28361) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS kamailio 5.3.2-1ubuntu0.1~esm2 Available with Ubuntu Pro Ubuntu 18.04 LTS kamailio 5.1.2-1ubuntu2+esm2 Available with UbuntuPro Ubuntu 16.04 LTS kamailio 4.3.4-1.1ubuntu2.1+esm2 Available with Ubuntu Pro After a standard system update you need to restart Kamailio to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7416-1 CVE-2016-2385, CVE-2018-14767, CVE-2020-28361 . Multiple security weaknesses in Kamailio need prompt updates for Ubuntu versions 20.04, 18.04, and 16.04. Essential patches are now accessible.. Kamailio Updates, Ubuntu Security, Buffer Overflow Risks. . LinuxSecurity.com Team

Calendar 2 Apr 07, 2025 Ubuntu
197

Debian 10: DLA-3438-1 Moderate: Kamailio DoS Attack Mitigation

It was discovered that there was a potential denial-of-service (DoS) attack in the Kamailio SIP telephony server. This was caused by the Kamailio server mishandling INVITE requests with duplicated fields. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3438-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Chris Lamb May 30, 2023 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : kamailio Version : 5.2.1-1+deb10u1 CVE ID : CVE-2020-27507 It was discovered that there was a potential denial-of-service (DoS) attack in the Kamailio SIP telephony server. This was caused by the Kamailio server mishandling INVITE requests with duplicated fields. For Debian 10 buster, this problem has been fixed in version 5.2.1-1+deb10u1. We recommend that you upgrade your kamailio packages. For the detailed security status of kamailio please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/kamailio Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Uncover the recent patch for Kamailio that tackles a service disruption vulnerability within Debian LTS DLA-3438-1.. Debian LTS, Kamailio, Denial Of Service Issue. . LinuxSecurity.com Team

Calendar 2 May 30, 2023 Debian LTS
172

Ubuntu 20.04 ESM: 6023-1 Critical: OpenSSH Connection Issue

Kamailio could be made to crash or run programs if it received specially crafted input.. =========================================================================Ubuntu Security Notice USN-6022-1 April 14, 2023 kamailio vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 ESM - Ubuntu 18.04 ESM - Ubuntu 16.04 ESM Summary: Kamailio could be made to crash or run programs if it received specially crafted input. Software Description: - kamailio: very fast, dynamic and configurable SIP server Details: It was discovered that Kamailio did not properly sanitize SIP messages under certain circumstances. An attacker could use this vulnerability to cause a denial of service or possibly execute arbitrary code. This issue only affected Ubuntu 16.04 ESM and 18.04 ESM. (CVE-2018-16657) It was discovered that Kamailio did not properly validate INVITE requests under certain circumstances. An attacker could use this vulnerability to cause a denial of service or possibly execute arbitrary code. (CVE-2020-27507) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 ESM: kamailio 5.3.2-1ubuntu0.1~esm1 Ubuntu 18.04 ESM: kamailio 5.1.2-1ubuntu2+esm1 Ubuntu 16.04 ESM: kamailio 4.3.4-1.1ubuntu2.1+esm1 In general, a standard system update will make all the necessary changes. References: CVE-2018-16657, CVE-2020-27507 . The April 14, 2023 advisory addresses vulnerabilities in Kamailio, which may result in potential system crashes and unauthorized code execution on Ubuntu platforms.. Kamailio, Ubuntu ESM, Security Notice, Software Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 14, 2023 Critical Ubuntu
172

Ubuntu 16.04 LTS: USN-4240-1 High: Kamailio Denial Of Service

kamailio could be made to crash if it opened a specially crafted file.. =========================================================================Ubuntu Security Notice USN-4240-1 January 16, 2020 kamailio vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: kamailio could be made to crash if it opened a specially crafted file. Software Description: - kamailio: very fast and configurable SIP proxy Details: It was discovered that Kamailio incorrectly handled a specially crafted file. An attacker could possibly use this issue to cause a denial of service or other unspecified impact. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: kamailio 4.3.4-1.1ubuntu2.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4240-1 CVE-2018-8828 Package Information: https://launchpad.net/ubuntu/+source/kamailio/4.3.4-1.1ubuntu2.1 . A security flaw in Kamailio present in Ubuntu 16.04 LTS can lead to a denial of service attack through the use of specifically designed files.. kamailio vulnerability, Ubuntu security, denial of service, software update, crash issue. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jan 16, 2020 Important Ubuntu
197

Debian 8: DLA-1503-1 Moderate: Kamailio DoS And Code Exec Issue

It was discovered that there was a denial of service and a potential arbitrary code execution vulnerability in the kamailio SIP server. A specially-crafted SIP message with an invalid "Via" header could cause a . Package : kamailio Version : 4.2.0-2+deb8u5 CVE ID : CVE-2018-16657 Debian Bug : #908324 It was discovered that there was a denial of service and a potential arbitrary code execution vulnerability in the kamailio SIP server. A specially-crafted SIP message with an invalid "Via" header could cause a segmentation fault and crash Kamailio due to missing input validation. For Debian 8 "Jessie", this issue has been fixed in kamailio version 4.2.0-2+deb8u5. We recommend that you upgrade your kamailio packages. Regards, - -- ,'`. : :' : Chris Lamb `. `'` This email address is being protected from spambots. You need JavaScript enabled to view it. / chris-lamb.co.uk `- . Enhance the kamailio version to address Denial of Service and code execution vulnerabilities. The updated version 4.2.0-2+deb8u5 mitigates these security risks.. kamailio security, Debian updates, denial of service fix, code execution issue. . LinuxSecurity.com Team

Calendar 2 Sep 12, 2018 Debian LTS
87

Debian: DSA-4292-1 Moderate: Kamailio Denial of Service Threat

Henning Westerholt discovered a flaw related to the Via header processing in kamailio, a very fast, dynamic and configurable SIP server. An unauthenticated attacker can take advantage of this flaw to mount a denial of service attack via a specially crafted SIP message . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4292-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso September 11, 2018 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : kamailio CVE ID : CVE-2018-16657 Debian Bug : 908324 Henning Westerholt discovered a flaw related to the Via header processing in kamailio, a very fast, dynamic and configurable SIP server. An unauthenticated attacker can take advantage of this flaw to mount a denial of service attack via a specially crafted SIP message with an invalid Via header. For the stable distribution (stretch), this problem has been fixed in version 4.4.4-2+deb9u3. We recommend that you upgrade your kamailio packages. For the detailed security status of kamailio please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/kamailio Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Enhancing Kamailio mitigates a vulnerability that allows denial of service assaults through specially designed SIP communications. Discover additional details.. Kamailio Security Update, Debian DSA-4292-1, Denial of Service Attack. . LinuxSecurity.com Team

Calendar 2 Sep 11, 2018 Debian
197

Debian 9 Stretch: DLA-1973-1 Severe: Apache Struts Remote Code Execution

CVE-2018-14767 Fix for missing input validation, which could result in denial of service and potentially the execution of arbitrary code. . Package : kamailio Version : 4.2.0-2+deb8u4 CVE ID : CVE-2018-14767 CVE-2018-14767 Fix for missing input validation, which could result in denial of service and potentially the execution of arbitrary code. For Debian 8 "Jessie", this problem has been fixed in version 4.2.0-2+deb8u4. We recommend that you upgrade your kamailio packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Update kamailio to address CVE-2018-14767, which presented vulnerabilities leading to potential denial of service and arbitrary code execution threats.. kamailio Security, Debian LTS Update, Denial of Service Fix, Software Vulnerability Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 19, 2018 Critical Debian LTS
87

Debian: DSA-4267-1 Critical: Kamailio To Header DoS Risk

Henning Westerholt discovered a flaw related to the To header processing in kamailio, a very fast, dynamic and configurable SIP server. Missing input validation in the build_res_buf_from_sip_req function could result in denial of service and potentially the execution of arbitrary code. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4267-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso August 08, 2018 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : kamailio CVE ID : CVE-2018-14767 Henning Westerholt discovered a flaw related to the To header processing in kamailio, a very fast, dynamic and configurable SIP server. Missing input validation in the build_res_buf_from_sip_req function could result in denial of service and potentially the execution of arbitrary code. For the stable distribution (stretch), this problem has been fixed in version 4.4.4-2+deb9u2. We recommend that you upgrade your kamailio packages. For the detailed security status of kamailio please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/kamailio Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Enhance the kamailio application to rectify a vulnerability in To header handling that could result in potential Denial of Service and unauthorized code execution.. kamailio Security Update,debian advisory,input validation flaw,DoS Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 08, 2018 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here