CVE-2018-2385
published 2018-02-14CVE-2018-2385: Under certain conditions a malicious user provoking a divide by zero crash can prevent legitimate users from accessing the SAP Internet Graphics Server, 7.20…
PriorityP428medium6.5CVSS 3.0
AVNACLPRLUINSUCNINAH
EPSS
0.92%
56.2th percentile
Under certain conditions a malicious user provoking a divide by zero crash can prevent legitimate users from accessing the SAP Internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53, and its services.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| kamailio | kamailio | >= 0 < 4.3.4-1.1ubuntu2.1+esm2 | 4.3.4-1.1ubuntu2.1+esm2 |
| kamailio | kamailio | >= 0 < 5.1.2-1ubuntu2+esm2 | 5.1.2-1ubuntu2+esm2 |
| kamailio | kamailio | >= 0 < 5.3.2-1ubuntu0.1~esm2 | 5.3.2-1ubuntu0.1~esm2 |
| sap | internet_graphics_server | — | — |
| sap | internet_graphics_server | — | — |
| sap | internet_graphics_server | — | — |
| sap | internet_graphics_server | — | — |
| sap | internet_graphics_server | — | — |
| sap_se | sap_internet_graphics_server | — | — |
| sap_se | sap_internet_graphics_server | — | — |
| sap_se | sap_internet_graphics_server | — | — |
| sap_se | sap_internet_graphics_server | — | — |
| sap_se | sap_internet_graphics_server | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
kamailio vulnerabilities
osv·2025-04-07·CVSS 9.8
CVE-2016-2385 kamailio vulnerabilities
kamailio vulnerabilities
Stelios Tsampas discovered that Kamailio did not correctly handle certain
memory operations, which could lead to a buffer overflow. A remote attacker
could possibly use this issue to cause a denial of service or execute
arbitrary code. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-2385)
Henning Westerholt discovered that Kamailio did not correctly handle
duplicated headers, which could lead to a segmentation fault. A remote
attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. This issue only affected Ubuntu 16.04 LTS and
Ubuntu 18.04 LTS. (CVE-2018-14767)
It was discovered that Kamailio did not correctly handle parsing certain
headers containing whitespace characters. An authenticated attacker could
possibly use t
GHSA
GHSA-f5fj-977p-5frv: Under certain conditions a malicious user provoking a divide by zero crash can prevent legitimate users from accessing the SAP Internet Graphics Serve
ghsa_unreviewed·2022-05-14
CVE-2018-2385 [MEDIUM] CWE-369 GHSA-f5fj-977p-5frv: Under certain conditions a malicious user provoking a divide by zero crash can prevent legitimate users from accessing the SAP Internet Graphics Serve
Under certain conditions a malicious user provoking a divide by zero crash can prevent legitimate users from accessing the SAP Internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53, and its services.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-02-14
Published