OpenSIPS has memory leak in cJSON lib
CVE-2023-28096
4.5MEDIUM
What is CVE-2023-28096?
OpenSIPS, a popular Session Initiation Protocol server, is affected by a memory leak identified in versions from the 2.3 branch through prior to 3.1.8 and 3.2.5. This vulnerability manifests in the parse_mi_request function, which is exploited when an attacker sends crafted JSON-RPC requests to the management interface. If the management interface is unintentionally exposed to the internet without adequate authentication, attackers can continuously send malformed requests, leading to gradual memory exhaustion and potential denial of service. The issue has been addressed in the latest releases, so users are encouraged to upgrade as soon as possible.
Affected Version(s)
opensips >= 2.3.0, < 3.1.8 < 2.3.0, 3.1.8
opensips >= 3.2.0, < 3.2.5 < 3.2.0, 3.2.5
