CVE-2020-27507

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
15/03/2023
Last modified:
27/02/2025

Description

The Kamailio SIP before 5.5.0 server mishandles INVITE requests with duplicated fields and overlength tag, leading to a buffer overflow that crashes the server or possibly have unspecified other impact.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kamailio:kamailio:*:*:*:*:*:*:*:* 5.5.0 (excluding)