Vulnerability Details CVE-2022-31003
Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, when parsing each line of a sdp message, `rest = record + 2` will access the memory behind `\0` and cause an out-of-bounds write. An attacker can send a message with evil sdp to FreeSWITCH, causing a crash or more serious consequence, such as remote code execution. Version 1.13.8 contains a patch for this issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.049
EPSS Ranking 89.1%
CVSS Severity
CVSS v3 Score 9.1
CVSS v2 Score 7.5
Products affected by CVE-2022-31003
-
cpe:2.3:a:signalwire:sofia-sip:1.11.0
-
cpe:2.3:a:signalwire:sofia-sip:1.11.1
-
cpe:2.3:a:signalwire:sofia-sip:1.11.2
-
cpe:2.3:a:signalwire:sofia-sip:1.11.3
-
cpe:2.3:a:signalwire:sofia-sip:1.11.4
-
cpe:2.3:a:signalwire:sofia-sip:1.11.5
-
cpe:2.3:a:signalwire:sofia-sip:1.11.6
-
cpe:2.3:a:signalwire:sofia-sip:1.11.7
-
cpe:2.3:a:signalwire:sofia-sip:1.11.8
-
cpe:2.3:a:signalwire:sofia-sip:1.11.9
-
cpe:2.3:a:signalwire:sofia-sip:1.12.0
-
cpe:2.3:a:signalwire:sofia-sip:1.12.1
-
cpe:2.3:a:signalwire:sofia-sip:1.12.2
-
cpe:2.3:a:signalwire:sofia-sip:1.12.3
-
cpe:2.3:a:signalwire:sofia-sip:1.12.4
-
cpe:2.3:a:signalwire:sofia-sip:1.13.2
-
cpe:2.3:a:signalwire:sofia-sip:1.13.3
-
cpe:2.3:a:signalwire:sofia-sip:1.13.4
-
cpe:2.3:a:signalwire:sofia-sip:1.13.5
-
cpe:2.3:a:signalwire:sofia-sip:1.13.6
-
cpe:2.3:a:signalwire:sofia-sip:1.13.7
-
cpe:2.3:o:debian:debian_linux:10.0