OpenSIPS has vulnerability in the parse_via() function
CVE-2023-27598
7.5HIGH
What is CVE-2023-27598?
A vulnerability in OpenSIPS allows an attacker to cause a Denial of Service by sending a specially crafted malformed 'Via' header. This triggers a segmentation fault in the 'calc_tag_suffix' function, leading to a crash of the OpenSIPS server. The issue arises when uninitialized strings are processed by the 'MD5StringArray' function, resulting in a system failure without requiring any special network privileges. Versions 3.1.7 and 3.2.4 provide fixes for this vulnerability.
Affected Version(s)
opensips < 3.1.7 < 3.1.7
opensips >= 3.2.0, < 3.2.4 < 3.2.0, 3.2.4
