CVE-2018-16657
published 2018-09-07CVE-2018-16657: In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with an invalid Via header causes a segmentation fault and crashes Kamailio. The reason…
PriorityP349critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
3.58%
88.1th percentile
In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with an invalid Via header causes a segmentation fault and crashes Kamailio. The reason is missing input validation in the crcitt_string_array core function for calculating a CRC hash for To tags. (An additional error is present in the check_via_address core function: this function also misses input validation.) This could result in denial of service and potentially the execution of arbitrary code.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | kamailio | < kamailio 5.1.4-1 (bookworm) | kamailio 5.1.4-1 (bookworm) |
| kamailio | kamailio | < 5.0.7 | 5.0.7 |
| kamailio | kamailio | >= 0 < 5.1.4-1 | 5.1.4-1 |
| kamailio | kamailio | >= 0 < 5.1.4-1 | 5.1.4-1 |
| kamailio | kamailio | >= 0 < 5.1.4-1 | 5.1.4-1 |
| kamailio | kamailio | >= 0 < 5.1.4-1 | 5.1.4-1 |
| kamailio | kamailio | >= 0 < 4.3.4-1.1ubuntu2.1+esm1 | 4.3.4-1.1ubuntu2.1+esm1 |
| kamailio | kamailio | >= 0 < 5.1.2-1ubuntu2+esm1 | 5.1.2-1ubuntu2+esm1 |
| kamailio | kamailio | >= 0 < 5.3.2-1ubuntu0.1~esm1 | 5.3.2-1ubuntu0.1~esm1 |
| kamailio | kamailio | >= 5.1.0 < 5.1.4 | 5.1.4 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
kamailio vulnerabilities
osv·2023-04-14·CVSS 9.8
CVE-2018-16657 [CRITICAL] kamailio vulnerabilities
kamailio vulnerabilities
It was discovered that Kamailio did not properly sanitize SIP messages under
certain circumstances. An attacker could use this vulnerability to cause a
denial of service or possibly execute arbitrary code. This issue only affected
Ubuntu 16.04 ESM and 18.04 ESM. (CVE-2018-16657)
It was discovered that Kamailio did not properly validate INVITE requests
under certain circumstances. An attacker could use this vulnerability to
cause a denial of service or possibly execute arbitrary code. (CVE-2020-27507)
GHSA
GHSA-4477-4jr7-cfjq: In Kamailio before 5
ghsa_unreviewed·2022-05-13
CVE-2018-16657 [CRITICAL] CWE-476 GHSA-4477-4jr7-cfjq: In Kamailio before 5
In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with an invalid Via header causes a segmentation fault and crashes Kamailio. The reason is missing input validation in the crcitt_string_array core function for calculating a CRC hash for To tags. (An additional error is present in the check_via_address core function: this function also misses input validation.) This could result in denial of service and potentially the execution of arbitrary code.
OSV
CVE-2018-16657: In Kamailio before 5
osv·2018-09-07·CVSS 9.8
CVE-2018-16657 [CRITICAL] CVE-2018-16657: In Kamailio before 5
In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with an invalid Via header causes a segmentation fault and crashes Kamailio. The reason is missing input validation in the crcitt_string_array core function for calculating a CRC hash for To tags. (An additional error is present in the check_via_address core function: this function also misses input validation.) This could result in denial of service and potentially the execution of arbitrary code.
Ubuntu
Kamailio vulnerabilities
vendor_ubuntu·2023-04-14·CVSS 9.8
CVE-2020-27507 [CRITICAL] Kamailio vulnerabilities
Title: Kamailio vulnerabilities
Summary: Kamailio could be made to crash or run programs if it received specially
crafted input.
It was discovered that Kamailio did not properly sanitize SIP messages under
certain circumstances. An attacker could use this vulnerability to cause a
denial of service or possibly execute arbitrary code. This issue only affected
Ubuntu 16.04 ESM and 18.04 ESM. (CVE-2018-16657)
It was discovered that Kamailio did not properly validate INVITE requests
under certain circumstances. An attacker could use this vulnerability to
cause a denial of service or possibly execute arbitrary code. (CVE-2020-27507)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2018-16657: kamailio - In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with an i...
vendor_debian·2018·CVSS 9.8
CVE-2018-16657 [CRITICAL] CVE-2018-16657: kamailio - In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with an i...
In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with an invalid Via header causes a segmentation fault and crashes Kamailio. The reason is missing input validation in the crcitt_string_array core function for calculating a CRC hash for To tags. (An additional error is present in the check_via_address core function: this function also misses input validation.) This could result in denial of service and potentially the execution of arbitrary code.
Scope: local
bookworm: resolved (fixed in 5.1.4-1)
bullseye: resolved (fixed in 5.1.4-1)
forky: resolved (fixed in 5.1.4-1)
sid: resolved (fixed in 5.1.4-1)
trixie: resolved (fixed in 5.1.4-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.debian.org/debian-lts-announce/2018/09/msg00013.htmlhttps://skalatan.de/blog/advisory-hw-2018-06https://www.debian.org/security/2018/dsa-4292https://lists.debian.org/debian-lts-announce/2018/09/msg00013.htmlhttps://skalatan.de/blog/advisory-hw-2018-06https://www.debian.org/security/2018/dsa-4292
2018-09-07
Published