Heap Buffer Overflow in GNU oSIP Products
CVE-2017-7853
7.5HIGH
Summary
In GNU oSIP versions 4.1.0 and 5.0.0, a vulnerability exists where a malformed SIP message can trigger a heap buffer overflow in the msg_osip_body_parse() function. This flaw can lead to a remote denial of service (DoS), potentially affecting the availability of the application.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved