#VU14789 Buffer overflow in Kamailio - CVE-2018-16657
Published: September 17, 2018
Kamailio
Kamailio
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input when processing SIP messages with an invalid "Via" header within the crcitt_string_array() and check_via_address() functions. A remote attacker can send a specially crafted SIP message, trigger memory corruption and crash the service or execute arbitrary code.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.