OSV-2024-1427

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/kamailio/OSV-2024-1427.yaml
JSON Data
https://api.osv.dev/v1/vulns/OSV-2024-1427
Published
2025-01-28T00:14:30.487391Z
Modified
2025-01-28T14:14:15.113804Z
Summary
Heap-buffer-overflow in extract_mediaip
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=391975654

Crash type: Heap-buffer-overflow READ 1
Crash state:
extract_mediaip
parse_sdp_session
parse_mixed_content
References

Affected packages

OSS-Fuzz / kamailio

Package

Name
kamailio
Purl
pkg:generic/kamailio

Affected ranges

Affected versions

5.*

5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.7.0
5.7.1
5.7.2
5.7.3
5.7.4
5.7.5
5.7.6
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.8.5

Ecosystem specific

{
    "severity": "MEDIUM"
}

Database specific

{
    "introduced_range": "22f9e269dd68edcb025e103d9aa1432423dd5550:199f13a7dfac8cd817850c6a6afe5ba510835418"
}