Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:15519
HistoryDec 29, 2006 - 12:00 a.m.

OpenSER OSP Module remote code execution

2006-12-2900:00:00
vulners.com
9

Synopsis: OpenSER OSP Module remote code execution
Product: OpenSER
Version: <=1.1.0

Issue:

A critical security vulnerability has been found in OpenSER Open
Settlement Protocol (OSP) module. OSP is an ETSI defined standard
for Inter-Domain VoIP pricing,authorization and usage exchange.

Details:

int validateospheader (struct sip_msg* msg, char* ignore1, char* ignore2)

This following fuction suffers from buffer overflow vulnerability, which
leads to memory corruption conditions. Due to memory corruption conditions
remote code execution is possible.

Affected Versions

OpenSER <= 1.1.0

Solution

Proper boundary checking.

Exploitation

Exploitation might be conducted by preparing a specially crafted
OSP header.

Kind regards,

Michal Bucko - sapheal
Senior Security Specialist
HACK.PL