← Späť na vyhľadávanie CVE

CVE-2026-45537

Popis

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the construct_uri() function concatenates multiple URI components (protocol, username, domain, port, params) into a fixed 1024-byte global BSS buffer without any bounds checking. When a routing script calls construct_uri() with an attacker-controlled username, a combined component length exceeding 1024 bytes overflows the buffer, corrupting adjacent global data with attacker-controlled content. The overflow reaches disable_503_translation, a global flag controlling SIP 503 response handling, allowing an attacker to deterministically set the flag via the URI username and alter the server-s routing behavior for subsequent messages. Because the same buffer is shared with contact_builder(), the overflow also corrupts that function-s data, and without a memory sanitizer the adjacent globals are silently overwritten on every request containing a long username. This issue has been fixed in versions 3.6.6 and 4.0.0-rc1.

CVSS 9.1EPSS 0.358%Riziko 0.94
Zobraziť zdroj
Zverejnené
2026-08-04 23:16:51
Posledná úprava
2026-08-05 18:17:11
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H