Heap-based buffer overflow in Kamailio - CVE-2018-8828
Published: April 3, 2018
Vulnerability identifier: #VU11488
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-8828
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition or execute arbitrary code on the target system.
The weakness exists in the tmx_check_pretran function in modules/tmx/tmx_pretran.c due to an off-by-one heap-based buffer overflow. A remote attacker can cause the service to crash and execute arbitrary code.
Successful exploitation of the vulnerability may result in system compromise.
The weakness exists in the tmx_check_pretran function in modules/tmx/tmx_pretran.c due to an off-by-one heap-based buffer overflow. A remote attacker can cause the service to crash and execute arbitrary code.
Successful exploitation of the vulnerability may result in system compromise.
Affected software
Kamailio
Debian Linux
kamailio (Ubuntu package)
kamailio (Alpine package)
Debian Linux
kamailio (Ubuntu package)
kamailio (Alpine package)
How to mitigate CVE-2018-8828
Update to versions 5.1.2, 5.0.6 or 4.4.7.
kamailio (Ubuntu package) - update to 4.3.4-1.1ubuntu2.1
kamailio (Alpine package) - update to 5.0.2-r4
kamailio (Alpine package) - update to 5.0.2-r4