Package        : kamailio
Version        : 4.2.0-2+deb8u5
CVE ID         : CVE-2018-16657
Debian Bug     : #908324

It was discovered that there was a denial of service and a potential
arbitrary code execution vulnerability in the kamailio SIP server.

A specially-crafted SIP message with an invalid "Via" header could cause a
segmentation fault and crash Kamailio due to missing input validation.

For Debian 8 "Jessie", this issue has been fixed in kamailio version
4.2.0-2+deb8u5.

We recommend that you upgrade your kamailio packages.


Regards,

- -- 
      ,''`.
     : :'  :     Chris Lamb
     `. `'`      lamby@debian.org / chris-lamb.co.uk
       `-

Debian LTS: DLA-1503-1: kamailio security update

September 12, 2018
It was discovered that there was a denial of service and a potential arbitrary code execution vulnerability in the kamailio SIP server

Summary

For Debian 8 "Jessie", this issue has been fixed in kamailio version
4.2.0-2+deb8u5.

We recommend that you upgrade your kamailio packages.


Regards,

- --
,''`.
: :' : Chris Lamb
`. `'` lamby@debian.org / chris-lamb.co.uk
`-



Severity
Package : kamailio
Version : 4.2.0-2+deb8u5
CVE ID : CVE-2018-16657
Debian Bug : #908324

Related News