Ubuntu Security Notice USN-6022-1 ≈ Packet Storm

Ubuntu Security Notice USN-6022-1 ≈ Packet Storm

Home[1] Files[2] News[3] &[SERVICES_TAB] Contact[4] Add New[5]

Ubuntu Security Notice USN-6022-1[6]
Authored by Ubuntu[7] | Site security.ubuntu.com[8]

Ubuntu Security Notice 6022-1 - It was discovered that Kamailio did not properly sanitize SIP messages under certain circumstances. An attacker could use this vulnerability to cause a denial of service or possibly execute arbitrary code. This issue only affected Ubuntu 16.04 ESM and 18.04 ESM. It was discovered that Kamailio did not properly validate INVITE requests under certain circumstances. An attacker could use this vulnerability to cause a denial of service or possibly execute arbitrary code.

systems | linux[9], ubuntu[10]
advisories | CVE-2018-16657[11], CVE-2020-27507[12]
SHA-256 | 7c6a30d8d416b241425f80caaed18c7b07803cd526df949946f1ceda2d2ab775

Change Mirror[16] Download[17]

        =========================================================================
Ubuntu Security Notice USN-6022-1
April 14, 2023
kamailio vulnerabilities
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 20.04 ESM
- Ubuntu 18.04 ESM
- Ubuntu 16.04 ESM
Summary:
Kamailio could be made to crash or run programs if it received specially
crafted input.
Software Description:
- kamailio: very fast, dynamic and configurable SIP server
Details:
It was discovered that Kamailio did not properly sanitize SIP messages under
certain circumstances. An attacker could use this vulnerability to cause a
denial of service or possibly execute arbitrary code. This issue only affected
Ubuntu 16.04 ESM and 18.04 ESM. (CVE-2018-16657)
It was discovered that Kamailio did not properly validate INVITE requests
under certain circumstances. An attacker could use this vulnerability to
cause a denial of service or possibly execute arbitrary code. (CVE-2020-27507)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 20.04 ESM:
kamailio 5.3.2-1ubuntu0.1~esm1
Ubuntu 18.04 ESM:
kamailio 5.1.2-1ubuntu2+esm1
Ubuntu 16.04 ESM:
kamailio 4.3.4-1.1ubuntu2.1+esm1
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6022-1
CVE-2018-16657, CVE-2020-27507

Login[18] or Register[19] to add favorites

File Archive:

April 2023

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa

File Tags

File Archives

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services[124]
Hosting By
Rokasec[125]
close

Read more

Image

Pensée du jour :

Ce que l'homme a fait ,

l'homme peut le défaire.

 

"No secure path in the world"