CVE-2018-14767: Input Validation
In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with a double "To" header and an empty "To" tag causes a segmentation fault and crash. The reason is missing input validation in the "buildresbuffromsipreq" core function. This could result in denial of service and potentially the execution of arbitrary code.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-14767?
CVE-2018-14767 has a severity rating that indicates it can lead to a denial of service due to a segmentation fault.
How do I fix CVE-2018-14767?
To fix CVE-2018-14767, upgrade Kamailio to version 5.2.1-1 or later.
Which versions of Kamailio are affected by CVE-2018-14767?
CVE-2018-14767 affects Kamailio versions prior to 5.0.7 and all versions of 5.1.x prior to 5.1.4.
What is the impact of CVE-2018-14767?
The impact of CVE-2018-14767 can result in a denial of service due to a crash of the Kamailio service.
Is CVE-2018-14767 specific to any operating systems?
CVE-2018-14767 is relevant to Debian systems running affected versions of Kamailio.