Heap-based buffer overflow in the encodemsg function in encodemsg.c in the SEAS module in Kamailio (formerly OpenSER and SER) before 4.3.5 allows remote attackers to cause a denial of service (memory corruption and process crash) or possibly execute arbitrary code via a large SIP packet.
[
{
"signature_version": "v1",
"source": "https://github.com/kamailio/kamailio/commit/f50c9c853e7809810099c970780c30b0765b0643",
"signature_type": "Function",
"target": {
"file": "modules/seas/encode_msg.c",
"function": "encode_msg"
},
"deprecated": false,
"id": "CVE-2016-2385-5ebe3977",
"digest": {
"function_hash": "91223690401395193117105268344153768528",
"length": 3699.0
}
},
{
"signature_version": "v1",
"source": "https://github.com/kamailio/kamailio/commit/f50c9c853e7809810099c970780c30b0765b0643",
"signature_type": "Line",
"target": {
"file": "modules/seas/encode_msg.c"
},
"deprecated": false,
"id": "CVE-2016-2385-fb9761ed",
"digest": {
"line_hashes": [
"221125951136127670003058648238912580109",
"185724564334586000378420562852713908961",
"162921764091139509490171745442129982752",
"13221970240674696037362829513348688430",
"80466780312632555410180150471875982336",
"124248757180292392880837749569296223629",
"156343932907448452507792033016352619609"
],
"threshold": 0.9
}
}
]