[sr-dev] Re: [kamailio/kamailio] Possible crash related to src/core/parser/digest/param_parser.c (Issue #3911)

2024-07-10 Thread Garnik Khroyan via sr-dev
Thank you for your detailed response and for looking into this issue. I appreciate you clarifying the origins of the code. Given your explanation, there was a misunderstanding about the source of the code in question. Unfortunately, I do not have a specific SIP request message that causes a cras

[sr-dev] [kamailio/kamailio] Outdated OpenSIPS Sources in Kamailio Project Lack Security Fixes (CVE-2023-28098) (Issue #3911)

2024-07-10 Thread Garnik Khroyan via sr-dev
### Description The master branch of the Kamailio project contains unpatched sources from OpenSIPS, in which [CVE-2023-28098](https://github.com/OpenSIPS/opensips/security/advisories/GHSA-jrqg-vppj-hr2h) was reported. The function `parse_param_name()` from `kamailio/src/core/parser/digest/param