QID 375458
Date Published: 2021-06-21
QID 375458: Freeswitch multiple buffer overflow vulnerability (FS-5566)
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a versatile software implementation that runs on any commodity hardware
A vulnerability is found in Freeswitch with following CVE:
CVE-2013-2238: Multiple buffer overflows in the switch_perform_substitution function in switch_regex.c in FreeSWITCH 1.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to the index and substituted variables.
Affected Versions:
FreeSWITCH before 1.2
QID Detection Logic (Authenticated):
The authenticated check looks for the installed version of Freeswitch.
Successful exploitation of this vulnerability allows unauthorized disclosure of information, unauthorized modification and disruption of service.
- Freeswitch buffer overflow -
freeswitch.org/confluence/display/FREESWITCH/Installation
CVEs related to QID 375458
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FS-5566 |
|