OpenSIPS has memory leak in cJSON lib
CVE-2023-28096

4.5MEDIUM

Key Information:

Vendor

Opensips

Status
Vendor
CVE Published:
15 March 2023

What is CVE-2023-28096?

OpenSIPS, a popular Session Initiation Protocol server, is affected by a memory leak identified in versions from the 2.3 branch through prior to 3.1.8 and 3.2.5. This vulnerability manifests in the parse_mi_request function, which is exploited when an attacker sends crafted JSON-RPC requests to the management interface. If the management interface is unintentionally exposed to the internet without adequate authentication, attackers can continuously send malformed requests, leading to gradual memory exhaustion and potential denial of service. The issue has been addressed in the latest releases, so users are encouraged to upgrade as soon as possible.

Affected Version(s)

opensips >= 2.3.0, < 3.1.8 < 2.3.0, 3.1.8

opensips >= 3.2.0, < 3.2.5 < 3.2.0, 3.2.5

References

CVSS V3.1

Score:
4.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.