kamailio: multiple /tmp file vulnerabilities
Helmut Grohne <helmut@...
2015-01-26 20:12:03 GMT
There are multiple /tmp file vulnerabilities to be found in the kamailio
SIP proxy. While many of these issues only affect configuration examples
or outdated components, some do affect the default configuration.
At this point, three issues are well understood:
* The kamctl administrative utility and default configuration would use
/tmp/kamailio_fifo (#712083, 2013, fixed in Debian's kamailio
* The kamcmd administrative utility and default configuration would use
/tmp/kamailio_ctl (#775681, 2015, patch available).
* The kamailio build process would use constant filenames in /tmp
allowing to elevate privileges to the build user (#775681, 2015,
The combined patch can be found at:
While the last issue definitely affects the upstream kamailio build,
arguably the first two issues are packaging specific. If they are
treated as such, it is worth noting that kamailio was never part of a
Debian stable release and thus this may not be worth issuing a CVE.