CVE-2018-8828

CRITICAL

Kamailio <4.4.7, 5.0.x <5.0.6, 5.1.x <5.1.2 - Buffer Overflow

Title source: llm
STIX 2.1

Description

A Buffer Overflow issue was discovered in Kamailio before 4.4.7, 5.0.x before 5.0.6, and 5.1.x before 5.1.2. A specially crafted REGISTER message with a malformed branch or From tag triggers an off-by-one heap-based buffer overflow in the tmx_check_pretran function in modules/tmx/tmx_pretran.c.

Scores

CVSS v3 9.8
EPSS 0.0329
EPSS Percentile 87.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-193 CWE-787
Status published
Products (3)
debian/debian_linux 8.0
debian/debian_linux 9.0
kamailio/kamailio < 4.4.7
Published Mar 20, 2018
Tracked Since Feb 18, 2026