Vulnerability Description
The Kamailio SIP before 5.5.0 server mishandles INVITE requests with duplicated fields and overlength tag, leading to a buffer overflow that crashes the server or possibly have unspecified other impact.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kamailio | Kamailio | < 5.5.0 |
Related Weaknesses (CWE)
References
- https://github.com/kamailio/kamailio/commit/ada3701d22b1fd579f06b4f54fa695fa988ePatch
- https://github.com/kamailio/kamailio/issues/2503ExploitIssue Tracking
- https://lists.debian.org/debian-lts-announce/2023/05/msg00030.html
- https://github.com/kamailio/kamailio/commit/ada3701d22b1fd579f06b4f54fa695fa988ePatch
- https://github.com/kamailio/kamailio/issues/2503ExploitIssue Tracking
- https://lists.debian.org/debian-lts-announce/2023/05/msg00030.html
FAQ
What is CVE-2020-27507?
CVE-2020-27507 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The Kamailio SIP before 5.5.0 server mishandles INVITE requests with duplicated fields and overlength tag, leading to a buffer overflow that crashes the server or possibly have unspecified other impac...
How severe is CVE-2020-27507?
CVE-2020-27507 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-27507?
Check the references section above for vendor advisories and patch information. Affected products include: Kamailio Kamailio.