CVE-2023-28099
- EPSS 0.91%
- Veröffentlicht 15.03.2023 23:15:09
- Zuletzt bearbeitet 21.11.2024 07:54:24
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.9 and 3.2.6, if `ds_is_in_list()` is used with an invalid IP address string (`NULL` is illegal input), OpenSIPS will attempt to print a string from a random ...
CVE-2023-28097
- EPSS 0.97%
- Veröffentlicht 15.03.2023 23:15:09
- Zuletzt bearbeitet 21.11.2024 07:54:23
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.9 and 3.2.6, a malformed SIP message containing a large _Content-Length_ value and a specially crafted Request-URI causes a segmentation fault in OpenSIPS. T...
CVE-2023-28096
- EPSS 0.77%
- Veröffentlicht 15.03.2023 22:15:10
- Zuletzt bearbeitet 21.11.2024 07:54:23
OpenSIPS, a Session Initiation Protocol (SIP) server implementation, has a memory leak starting in the 2.3 branch and priot to versions 3.1.8 and 3.2.5. The memory leak was detected in the function `parse_mi_request` while performing coverage-guided ...
CVE-2023-28095
- EPSS 0.97%
- Veröffentlicht 15.03.2023 22:15:10
- Zuletzt bearbeitet 21.11.2024 07:54:23
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.1.7 and 3.2.4 have a potential issue in `msg_translator.c:2628` which might lead to a server crash. This issue was found while fuzzing the function `build_res_...
CVE-2023-27601
- EPSS 0.99%
- Veröffentlicht 15.03.2023 22:15:10
- Zuletzt bearbeitet 21.11.2024 07:53:14
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.7 and 3.2.4, OpenSIPS crashes when a malformed SDP body is received and is processed by the `delete_sdp_line` function in the sipmsgops module. This issue ca...
CVE-2023-27600
- EPSS 0.99%
- Veröffentlicht 15.03.2023 22:15:10
- Zuletzt bearbeitet 21.11.2024 07:53:14
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.7 and 3.2.4, OpenSIPS crashes when a malformed SDP body is received and is processed by the `delete_sdp_line` function in the sipmsgops module. This issue ca...
CVE-2023-27599
- EPSS 0.97%
- Veröffentlicht 15.03.2023 21:15:09
- Zuletzt bearbeitet 21.11.2024 07:53:14
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.7 and 3.2.4, when the function `append_hf` handles a SIP message with a malformed To header, a call to the function `abort()` is performed, resulting in a cr...
CVE-2023-27598
- EPSS 0.97%
- Veröffentlicht 15.03.2023 21:15:09
- Zuletzt bearbeitet 21.11.2024 07:53:13
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.7 and 3.2.4, sending a malformed `Via` header to OpenSIPS triggers a segmentation fault when the function `calc_tag_suffix` is called. A specially crafted `V...
CVE-2023-27597
- EPSS 0.74%
- Veröffentlicht 15.03.2023 21:15:09
- Zuletzt bearbeitet 21.11.2024 07:53:13
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.8 and 3.2.5, when a specially crafted SIP message is processed by the function `rewrite_ruri`, a crash occurs due to a segmentation fault. This issue causes ...
CVE-2023-27596
- EPSS 0.74%
- Veröffentlicht 15.03.2023 21:15:08
- Zuletzt bearbeitet 21.11.2024 07:53:13
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.8 and 3.2.5, OpenSIPS crashes when a malformed SDP body is sent multiple times to an OpenSIPS configuration that makes use of the `stream_process` function. ...