Kamailio (successor of former OpenSER and SER) is an Open Source SIP Server released under GPL. It can be used to build large platforms for VoIP and realtime communications, presence, WebRTC, Instant messaging and other applications. A heap overflow was found in Kamailio version 4.3.4 (possibly affecting earlier versions also). The heap overflow takes place in the encode_msg function of the SEAS module and can be triggered remotely if the module is enabled. A technical analysis of the vulnerability can be found here: https://census-labs.com/news/2016/03/30/kamailio-seas-heap-overflow/ The vulnerability may allow an attacker to cause memory corruption, process termination or potentially remote code execution. This defect has been fixed in version 4.3.5 of Kamailio. Administrators of affected systems are strongly advised to upgrade Kamailio to the latest stable release. Disclosure Timeline ------------------- Vendor Contact: February 12th, 2016 CVE assignment: February 15th, 2016 Vendor Patch Release: March 3rd, 2016 Public Advisory: March 30th, 2016 Regards, Stelios Tsampas IT Security Researcher CENSUS S.A.