7.5
CVSSv3

CVE-2017-11521

Published: 22/07/2017 Updated: 06/04/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The SdpContents::Session::Medium::parse function in resip/stack/SdpContents.cxx in reSIProcate 1.10.2 allows remote malicious users to cause a denial of service (memory consumption) by triggering many media connections.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

resiprocate resiprocate 1.10.2

debian debian linux 8.0

debian debian linux 9.0

Vendor Advisories

Debian Bug report logs - #869404 resiprocate: CVE-2017-11521: Adding too many media connections may lead to memory exhaustion Package: src:resiprocate; Maintainer for src:resiprocate is Debian VoIP Team <pkg-voip-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 23 ...

Exploits

reSIProcate version 1102 suffers from a heap overflow vulnerability ...