Heap Buffer Overflow Vulnerability in GNU oSIP by GNU
CVE-2016-10324
9.8CRITICAL
Summary
A vulnerability exists in the GNU oSIP version 4.1.0, where a malformed SIP message can trigger a heap buffer overflow in the osip_clrncpy() function, located in osipparser2/osip_port.c. This flaw can potentially allow attackers to manipulate memory, leading to application crashes or arbitrary code execution. It is crucial for users of this software to apply any necessary patches and monitor their systems for unusual activity.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved