OpenSER OSP Module remote code execution Dec 28 2006 12:22PM
sapheal hack pl
Synopsis: OpenSER OSP Module remote code execution

Product: OpenSER

Version: <=1.1.0

Issue:

======

A critical security vulnerability has been found in OpenSER Open

Settlement Protocol (OSP) module. OSP is an ETSI defined standard

for Inter-Domain VoIP pricing,authorization and usage exchange.

Details:

========

int validateospheader (struct sip_msg* msg, char* ignore1, char* ignore2)

This following fuction suffers from buffer overflow vulnerability, which

leads to memory corruption conditions. Due to memory corruption conditions

remote code execution is possible.

Affected Versions

=================

OpenSER <= 1.1.0

Solution

=========

Proper boundary checking.

Exploitation

============

Exploitation might be conducted by preparing a specially crafted

OSP header.

Kind regards,

Micha³ Buæko - sapheal

Senior Security Specialist

HACK.PL

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus