Kamailio 5.3.4

CPE Details

Kamailio 5.3.4
5.3.4
2020-12-01
12h39 +00:00
2020-12-01
12h39 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:kamailio:kamailio:5.3.4:*:*:*:*:*:*:*

Informations

Vendor

kamailio

Product

kamailio

Version

5.3.4

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2020-27507 2023-03-15 00h00 +00:00 The Kamailio SIP before 5.5.0 server mishandles INVITE requests with duplicated fields and overlength tag, leading to a buffer overflow that crashes the server or possibly have unspecified other impact.
9.8
Critique
CVE-2020-28361 2020-11-18 12h34 +00:00 Kamailio before 5.4.0, as used in Sip Express Router (SER) in Sippy Softswitch 4.5 through 5.2 and other products, allows a bypass of a header-removal protection mechanism via whitespace characters. This occurs in the remove_hf function in the Kamailio textops module. Particular use of remove_hf in Sippy Softswitch may allow skilled attacker having a valid credential in the system to disrupt internal call start/duration accounting mechanisms leading potentially to a loss of revenue.
5.4
Moyen