← Vulnerability feed

Vulnerability record · CVE-2013-7426 · published 29 August 2017

CVE-2013-7426: Kamailio unrestricted file upload vulnerability

Kamailio · Kamailio

Insecure Temporary file vulnerability in /tmp/kamailio_fifo in kamailio 4.0.1.

9.8 CVSS 3.0 Critical EPSS 2.2% · top 18.5% CWE-434 · Unrestricted file upload
9.8CVSS 3.0 base score, v2 7.5
2.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Insecure Temporary file vulnerability in /tmp/kamailio_fifo in kamailio 4.0.1.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.openwall.com/lists/oss-security/2015/02/12/7 Mailing ListPatchThird Party Advisory
http://www.securityfocus.com/bid/100537 Third Party AdvisoryVDB Entry
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=712083 Issue TrackingThird Party Advisory
http://www.openwall.com/lists/oss-security/2015/02/12/7 Mailing ListPatchThird Party Advisory
http://www.securityfocus.com/bid/100537 Third Party AdvisoryVDB Entry
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=712083 Issue TrackingThird Party Advisory

Track CVE-2013-7426 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-27507Kamailio classic buffer overflow vulnerabilityThe Kamailio SIP before 5.5.0 server mishandles INVITE requests with duplicated fields and overlength tag, leading to a buffer overflow that crashes …EPSS 1.2%9.8CVE-2018-16657Debian linux null pointer dereference vulnerabilityIn Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with an invalid Via header causes a segmentation fault and crashes Kamailio. T…EPSS 3.6%9.8CVE-2018-14767Debian linux improper input validation vulnerabilityIn Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with a double "To" header and an empty "To" tag causes a segmentation fault an…EPSS 29%9.8CVE-2018-8828Kamailio out-of-bounds write vulnerabilityA Buffer Overflow issue was discovered in Kamailio before 4.4.7, 5.0.x before 5.0.6, and 5.1.x before 5.1.2. A specially crafted REGISTER message wit…EPSS 30%9.8CVE-2016-2385Debian linux memory buffer overflow vulnerabilityHeap-based buffer overflow in the encode_msg function in encode_msg.c in the SEAS module in Kamailio (formerly OpenSER and SER) before 4.3.5 allows r…EPSS 31%7.8CVE-2015-1590Kamailio permissions and access controls vulnerabilityThe kamcmd administrative utility and default configuration in kamailio before 4.3.0 use /tmp/kamailio_ctl.EPSS 0.43%7.8CVE-2015-1591Kamailio permissions and access controls vulnerabilityThe kamailio build in kamailio before 4.2.0-2 process allows local users to gain privileges.EPSS 0.39%7.5CVE-2026-52022Kamailio uncontrolled resource consumption vulnerabilityAn issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the IMS P-CSCF registration handling componentsEPSS 0.58%

Source: NIST National Vulnerability Database (record CVE-2013-7426), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.