UBUNTU-CVE-2016-2385
Dashboard / Vulnerabilities / UBUNTU-CVE-2016-2385
UBUNTU-CVE-2016-2385
Summary:
Details: Heap-based buffer overflow in the encode_msg function in encode_msg.c in the SEAS module in Kamailio (formerly OpenSER and SER) before 4.3.5 allows remote attackers to cause a denial of service (memory corruption and process crash) or possibly execute arbitrary code via a large SIP packet.
References: https://ubuntu.com/security/CVE-2016-2385, https://github.com/kamailio/kamailio/commit/f50c9c853e7809810099c970780c30b0765b0643, http://www.openwall.com/lists/oss-security/2016/02/15/4, https://www.cve.org/CVERecord?id=CVE-2016-2385, https://ubuntu.com/security/notices/USN-7416-1
Affected packages
Package
Name: kamailio
Purl: pkg:deb/ubuntu/[email protected]+esm2?arch=source&distro=esm-apps/xenial
Affected ranges
Type: ECOSYSTEM
Events:
