Kamailio SEAS module Heap Buffer Overflow Vulnerability (CVE-2016-2385)
Kamailio SEAS module Heap Buffer Overflow Vulnerability (CVE-2016-2385)
Release date:
Updated on:
Affected Systems:
Kamailio 4.3.4
Description:
CVE (CAN) ID: CVE-2016-2385
Kamailio is an open-source SIP server used to construct large-scale platforms for VoIP, real-time communication, WebRTC, and other applications.
The encode_msg function of seas module of Kamailio 4.3.4 has a heap overflow vulnerability, which can cause memory corruption, process interruption, or remote code execution by remote attackers.
<* Source: Stelios Tsampas
*>
Suggestion:
Vendor patch:
Kamailio
--------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://www.kamailio.org/w/
Reference: https://census-labs.com/news/2016/03/30/kamailio-seas-heap-overflow/
Compile Kamailio 4.1.0 in Ubuntu 12.04
Kamailio Installation Guide
The Installation Process of siremis is attached. Siremis is the web management interface of kamailio. See
Kamailio details: click here
Kamailio: click here
This article permanently updates the link address: