CVE-2022-31002: Out-of-bounds Read in Sofia-SIP
Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, an attacker can send a message with evil sdp to FreeSWITCH, which may cause a crash. This type of crash may be caused by a URL ending with %. Version 1.13.8 contains a patch for this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-31002?
CVE-2022-31002 refers to a vulnerability in the Sofia-SIP Session Initiation Protocol (SIP) User-Agent library that allows an attacker to send a malicious message to FreeSWITCH, potentially causing a crash.
What is the severity of CVE-2022-31002?
The severity of CVE-2022-31002 is high, with a severity value of 7.5.
How does CVE-2022-31002 impact Sofia-SIP?
CVE-2022-31002 can be exploited by sending a message with evil Session Description Protocol (SDP) to FreeSWITCH, leading to a potential crash.
Which versions of Sofia-SIP are affected by CVE-2022-31002?
Versions prior to 1.13.8 of Sofia-SIP are affected by CVE-2022-31002.
How can I fix the CVE-2022-31002 vulnerability in Sofia-SIP?
To fix the CVE-2022-31002 vulnerability in Sofia-SIP, update to version 1.13.8 or later, which contains a patch for this issue.