CVE-2023-27597: OpenSIPS has vulnerability in the parse_uri() function
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.8 and 3.2.5, when a specially crafted SIP message is processed by the function rewriteruri, a crash occurs due to a segmentation fault. This issue causes the server to crash. It affects configurations containing functions that make use of the affected code, such as the function setport. This issue has been fixed in version 3.1.8 and 3.2.5.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-27597?
CVE-2023-27597 has been classified as a high-severity vulnerability due to its potential to cause server crashes.
How do I fix CVE-2023-27597?
To fix CVE-2023-27597, upgrade OpenSIPS to version 3.1.8 or 3.2.5 or later.
What types of systems are affected by CVE-2023-27597?
CVE-2023-27597 affects OpenSIPS versions prior to 3.1.8 and between 3.2.0 and 3.2.5.
What impact does CVE-2023-27597 have on OpenSIPS?
CVE-2023-27597 can lead to a segmentation fault, resulting in the OpenSIPS server crashing when processing crafted SIP messages.
Is there a workaround for CVE-2023-27597?
There is no documented workaround for CVE-2023-27597; upgrading to a secure version is the recommended solution.