Stack Buffer Overflow Vulnerability in sngrep Affects All Versions
CVE-2024-3120
9CRITICAL
What is CVE-2024-3120?
A stack-buffer overflow vulnerability has been identified in all versions of sngrep from 1.4.1 onwards. This issue arises from insufficient bounds checking when handling 'Content-Length' and 'Warning' headers in the sip_validate_packet and sip_parse_extra_headers functions. Attackers can exploit this flaw using specially crafted SIP messages to execute arbitrary code or trigger a denial of service (DoS), potentially compromising system integrity and availability.
Affected Version(s)
sngrep Linux 1.4.1 <= 1.8.0
