OSV-2024-1244

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/kamailio/OSV-2024-1244.yaml
JSON Data
https://api.osv.dev/v1/vulns/OSV-2024-1244
Published
2024-10-27T00:10:45.337287Z
Modified
2024-11-06T14:24:14.483448Z
Summary
Heap-buffer-overflow in extract_fmtp
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=375237153

Crash type: Heap-buffer-overflow READ 6
Crash state:
extract_fmtp
parse_sdp_session
parse_mixed_content
References

Affected packages

OSS-Fuzz / kamailio

Package

Name
kamailio
Purl
pkg:generic/kamailio

Affected ranges

Affected versions

5.*

5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.7.0
5.7.1
5.7.2
5.7.3
5.7.4
5.7.5
5.7.6
5.8.0
5.8.1
5.8.2
5.8.3

Ecosystem specific

{
    "severity": "MEDIUM"
}

Database specific

{
    "introduced_range": "22f9e269dd68edcb025e103d9aa1432423dd5550:199f13a7dfac8cd817850c6a6afe5ba510835418",
    "fixed_range": "a6b924be7fd7d4ce6a92ad5a0247077b09a29474:d10257fbfdbb3e3e73c0fe60a224585822bdd7b3"
}