Debian Security Advisory
DSA-4267-1 kamailio -- security update
- Date Reported:
- 08 Aug 2018
- Affected Packages:
- kamailio
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2018-14767.
- More information:
-
Henning Westerholt discovered a flaw related to the To header processing in kamailio, a very fast, dynamic and configurable SIP server. Missing input validation in the build_res_buf_from_sip_req function could result in denial of service and potentially the execution of arbitrary code.
For the stable distribution (stretch), this problem has been fixed in version 4.4.4-2+deb9u2.
We recommend that you upgrade your kamailio packages.
For the detailed security status of kamailio please refer to its security tracker page at: https://security-tracker.debian.org/tracker/kamailio