Home page logo

bugtraq logo Bugtraq mailing list archives

OpenSER OSP Module remote code execution
From: sapheal () hack pl
Date: Thu, 28 Dec 2006 13:22:38 +0100

Synopsis:  OpenSER OSP Module remote code execution
Product:   OpenSER
Version:   <=1.1.0


A critical security vulnerability has been found in OpenSER Open
Settlement Protocol (OSP) module. OSP is an ETSI defined standard
for Inter-Domain VoIP pricing,authorization and usage exchange. 


int validateospheader (struct sip_msg* msg, char* ignore1, char* ignore2) 

This following fuction suffers from buffer overflow vulnerability, which
leads to memory corruption conditions. Due to memory corruption conditions
remote code execution is possible.

Affected Versions

OpenSER <= 1.1.0


Proper boundary checking.


Exploitation might be conducted by preparing a specially crafted
OSP header.

Kind regards,

Michał Bućko - sapheal
Senior Security Specialist

  By Date           By Thread  

Current thread:
  • OpenSER OSP Module remote code execution sapheal (Dec 28)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]