OSV-2024-1206

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/kamailio/OSV-2024-1206.yaml
JSON Data
https://api.osv.dev/v1/vulns/OSV-2024-1206
Published
2024-10-11T00:13:47.835312Z
Modified
2024-10-11T00:13:47.835630Z
Summary
Heap-buffer-overflow in extract_sendrecv_mode
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=372515090

Crash type: Heap-buffer-overflow READ 6
Crash state:
extract_sendrecv_mode
parse_sdp_session
parse_mixed_content
References

Affected packages

OSS-Fuzz / kamailio

Package

Name
kamailio
Purl
pkg:generic/kamailio

Affected ranges

Type
GIT
Repo
https://github.com/kamailio/kamailio
Events

Affected versions

5.*

5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.7.0
5.7.1
5.7.2
5.7.3
5.7.4
5.7.5
5.7.6
5.8.0
5.8.1
5.8.2
5.8.3

Ecosystem specific

{
    "severity": "MEDIUM"
}

Database specific

{
    "introduced_range": "22f9e269dd68edcb025e103d9aa1432423dd5550:199f13a7dfac8cd817850c6a6afe5ba510835418",
    "fixed_range": "66fe6eb71e58a02222d1a2fb00f9a0cdb863134c:e802f9187383feb7fdd96c4ded44fda403da4535"
}