The Kamailio SIP before 5.5.0 server mishandles INVITE requests with duplicated fields and overlength tag, leading to a buffer overflow that crashes the server or possibly have unspecified other impact.
{ "vanir_signatures": [ { "digest": { "function_hash": "114316787224008964060248551968142233233", "length": 5300.0 }, "id": "CVE-2020-27507-0f70405b", "source": "https://github.com/kamailio/kamailio/commit/ada3701d22b1fd579f06b4f54fa695fa988e685f", "signature_type": "Function", "signature_version": "v1", "target": { "file": "src/modules/tm/t_msgbuilder.c", "function": "build_local_reparse" }, "deprecated": false }, { "digest": { "threshold": 0.9, "line_hashes": [ "244853819632765666073470842383683866680", "309167914881267807067215393314209984378", "233439026921492938211186183726557894273", "208478992480895715052172760531444741065", "98354347111107095773283480051690903316", "247666984453264000557428290713400669560", "277341704800932035958278878296165285977", "49356985030235935141449157401671665168", "15339373829704610241290920527076321161", "31324623973729729167260177738395379528", "310933076340412908423676356898652860946", "66769361556101405352954786194173159080", "101009839613711374645398553541089531696", "325287812837834173263465784407286470343", "28586271685691763243815955786253738952", "85518898683136243251146147658562743361", "197206930985602377692022338456147357993", "112024895113507828268144598513674332814", "113539570549639087535043534570725549278" ] }, "id": "CVE-2020-27507-5e3d2850", "source": "https://github.com/kamailio/kamailio/commit/ada3701d22b1fd579f06b4f54fa695fa988e685f", "signature_type": "Line", "signature_version": "v1", "target": { "file": "src/modules/tm/t_msgbuilder.c" }, "deprecated": false } ] }