7.5
CVSSv3

CVE-2017-7853

Published: 13/04/2017 Updated: 04/11/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

In libosip2 in GNU oSIP 4.1.0 and 5.0.0, a malformed SIP message can lead to a heap buffer overflow in the msg_osip_body_parse() function defined in osipparser2/osip_message_parse.c, resulting in a remote DoS.

Vulnerable Product Search on Vulmon Subscribe to Product

gnu osip 5.0.0

Vendor Advisories

Debian Bug report logs - #860287 libosip2: CVE-2016-10324 CVE-2016-10325 CVE-2016-10326 CVE-2017-7853 Package: src:libosip2; Maintainer for src:libosip2 is Debian VoIP Team <pkg-voip-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 14 Apr 2017 06:09:01 UTC Severit ...