telephony/net/kamailio-5.x
Sebastian Kemper 8ecfc4b0b1 kamailio-5.x: add fix for CVE-2018-16657
In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with
an invalid Via header causes a segmentation fault and crashes Kamailio. The
reason is missing input validation in the crcitt_string_array core function
for calculating a CRC hash for To tags. (An additional error is present in
the check_via_address core function: this function also misses input
validation.) This could result in denial of service and potentially the
execution of arbitrary code.

Patch from upstream.

Signed-off-by: Sebastian Kemper <sebastian_ml@gmx.net>
2018-09-12 20:27:33 +02:00
..
files kamailio-5.x: introduce new package 2017-08-13 20:29:23 +02:00
patches kamailio-5.x: add fix for CVE-2018-16657 2018-09-12 20:27:33 +02:00
Makefile kamailio-5.x: add fix for CVE-2018-16657 2018-09-12 20:27:33 +02:00