CyberRota Analysis
AI-GeneratedA stack buffer overflow vulnerability in SIPp versions up to 3.7.7 allows a malicious SIP server to exploit oversized algorithm parameters in the createAuthHeader() function, potentially leading to client process crashes. This high-severity flaw poses a significant risk to organizations relying on SIPp for SIP protocol testing and should be prioritized for remediation by users and administrators of affected systems. Immediate action is recommended to mitigate the risk of service disruption and potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authentication challenges with oversized algorithm parameters. A malicious SIP server can send a crafted 401 or 407 challenge to corrupt the stack and crash the client process.