CVE-2023-28095: OpenSIPS has vulnerability in the building the local negative replies
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.1.7 and 3.2.4 have a potential issue in msgtranslator.c:2628 which might lead to a server crash. This issue was found while fuzzing the function buildresbuffromsipreq but could not be reproduced against a running instance of OpenSIPS. This issue could not be exploited against a running instance of OpenSIPS since no public function was found to make use of this vulnerable code. Even in the case of exploitation through unknown vectors, it is highly unlikely that this issue would lead to anything other than Denial of Service. This issue has been fixed in versions 3.1.7 and 3.2.4.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-28095?
CVE-2023-28095 is a medium severity vulnerability that may lead to a server crash in affected OpenSIPS versions.
How do I fix CVE-2023-28095?
To fix CVE-2023-28095, upgrade OpenSIPS to version 3.1.7 or 3.2.4 or later.
Which versions of OpenSIPS are affected by CVE-2023-28095?
OpenSIPS versions prior to 3.1.7 and versions between 3.2.0 and 3.2.4 are affected by CVE-2023-28095.
What should I do if I cannot upgrade OpenSIPS for CVE-2023-28095?
If you cannot upgrade, mitigate the issue by implementing additional security controls and monitoring for potential crashes.
Is there a known exploit for CVE-2023-28095?
As of now, there are no publicly disclosed exploits specific to CVE-2023-28095.