The Kamailio SIP before 5.5.0 server mishandles INVITE requests with duplicated fields and overlength tag, leading to a buffer overflow that crashes the server or possibly have unspecified other impact.
[
{
"id": "CVE-2020-27507-0f70405b",
"signature_type": "Function",
"digest": {
"length": 5300.0,
"function_hash": "114316787224008964060248551968142233233"
},
"signature_version": "v1",
"target": {
"function": "build_local_reparse",
"file": "src/modules/tm/t_msgbuilder.c"
},
"source": "https://github.com/kamailio/kamailio/commit/ada3701d22b1fd579f06b4f54fa695fa988e685f",
"deprecated": false
},
{
"id": "CVE-2020-27507-5e3d2850",
"signature_type": "Line",
"digest": {
"line_hashes": [
"244853819632765666073470842383683866680",
"309167914881267807067215393314209984378",
"233439026921492938211186183726557894273",
"208478992480895715052172760531444741065",
"98354347111107095773283480051690903316",
"247666984453264000557428290713400669560",
"277341704800932035958278878296165285977",
"49356985030235935141449157401671665168",
"15339373829704610241290920527076321161",
"31324623973729729167260177738395379528",
"310933076340412908423676356898652860946",
"66769361556101405352954786194173159080",
"101009839613711374645398553541089531696",
"325287812837834173263465784407286470343",
"28586271685691763243815955786253738952",
"85518898683136243251146147658562743361",
"197206930985602377692022338456147357993",
"112024895113507828268144598513674332814",
"113539570549639087535043534570725549278"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "src/modules/tm/t_msgbuilder.c"
},
"source": "https://github.com/kamailio/kamailio/commit/ada3701d22b1fd579f06b4f54fa695fa988e685f",
"deprecated": false
}
]