ubuntu · CVE-2016-2385

Quick triage

Priority: medium Published: 2016-04-11 15:59:00 UTC Updated: 2025-08-25 21:57:18 UTC

View at Official ubuntu advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2016-2385 medium priority: Ubuntu including 1 source packages (kamailio), 22 status rows across 22 suites (artful, bionic, cosmic, disco, eoan, focal, groovy, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, precise, trusty, upstream, wily, xenial, yakkety, zesty): not-affected 14, ignored 4, DNE 2, released 2.

Description:

Heap-based buffer overflow in the encode_msg function in encode_msg.c in the SEAS module in Kamailio (formerly OpenSER and SER) before 4.3.5 allows remote attackers to cause a denial of service (memory corruption and process crash) or possibly execute arbitrary code via a large SIP packet.

cvelogic Threat Intelligence