OpenSIPS has vulnerability in the building the local negative replies
CVE-2023-28095
7.5HIGH
What is CVE-2023-28095?
OpenSIPS, a widely used Session Initiation Protocol (SIP) server, has a vulnerability in the msg_translator.c file that could potentially lead to a server crash. Although this issue was identified during fuzz testing and pertains to the function build_res_buf_from_sip_req, it could not be replicated against an active OpenSIPS instance. Importantly, no public functions were linked to this vulnerability, rendering exploitation extremely improbable. Should exploitation occur through undiscovered methods, it is anticipated to result solely in Denial of Service. The vulnerability has been resolved in OpenSIPS versions 3.1.7 and 3.2.4.
Affected Version(s)
opensips < 3.1.7 < 3.1.7
opensips >= 3.2.0, < 3.2.4 < 3.2.0, 3.2.4
