CyberRota Analysis
AI-GeneratedA heap-based buffer overflow vulnerability exists in the CDP Diameter Receiver component of Kamailio versions up to 5.8.8, 6.0.7, 6.1.4, and 6.2.0-dev1, which can be exploited remotely due to public availability of the exploit. This flaw could allow attackers to manipulate the application, potentially leading to severe impacts on system integrity and availability. Organizations using affected versions should prioritize upgrading to version 6.0.8 or later to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_malloc of the file src/modules/cdp/receiver.c of the component CDP Diameter Receiver. Executing a manipulation can lead to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 6.0.8 is sufficient to resolve this issue. This patch is called 38711a3e788de0130d48cb485578c482b57d9351/4f62235b6f477b649c5cc18b0c81b4e26c949b98/4f62235b6f477b649c5cc18b0c81b4e26c949b98. You should upgrade the affected component.