A Buffer Overflow issue was discovered in Kamailio before 4.4.7, 5.0.x before 5.0.6, and 5.1.x before 5.1.2. A specially crafted REGISTER message with a malformed branch or From tag triggers an off-by-one heap-based buffer overflow in the tmxcheckpretran function in modules/tmx/tmx_pretran.c.
[
{
"target": {
"file": "src/modules/tmx/tmx_pretran.c"
},
"digest": {
"line_hashes": [
"202312855581435197133371407321087176701",
"277043145890525527711492030391328171372",
"78360990353905610262814467092084753475",
"38820567475123698968890758151512420525"
],
"threshold": 0.9
},
"signature_version": "v1",
"source": "https://github.com/kamailio/kamailio/commit/e1d8008a09d9390ebaf698abe8909e10dfec4097",
"deprecated": false,
"signature_type": "Line",
"id": "CVE-2018-8828-96b9e290"
},
{
"target": {
"function": "tmx_check_pretran",
"file": "src/modules/tmx/tmx_pretran.c"
},
"digest": {
"length": 5848.0,
"function_hash": "294881891307122545872262304880529037414"
},
"signature_version": "v1",
"source": "https://github.com/kamailio/kamailio/commit/e1d8008a09d9390ebaf698abe8909e10dfec4097",
"deprecated": false,
"signature_type": "Function",
"id": "CVE-2018-8828-da97b9af"
}
]