755
VMScore

CVE-2018-12584

Published: 16/07/2018 Updated: 18/04/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The ConnectionBase::preparseNewBytes function in resip/stack/ConnectionBase.cxx in reSIProcate up to and including 1.10.2 allows remote malicious users to cause a denial of service (buffer overflow) or possibly execute arbitrary code when TLS communication is enabled.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

resiprocate resiprocate

debian debian linux 8.0

debian debian linux 9.0

Vendor Advisories

Debian Bug report logs - #905495 resiprocate: CVE-2018-12584 Package: src:resiprocate; Maintainer for src:resiprocate is Debian VoIP Team <pkg-voip-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 5 Aug 2018 13:21:02 UTC Severity: grave Tags: patch, security, ups ...

Exploits

''' CVE ID: CVE-2018-12584 TIMELINE Bug report with test code sent to main reSIProcate developers: 2018-06-15 Patch created by Scott Godin: 2018-06-18 CVE ID assigned: 2018-06-19 Patch committed to reSIProcate repository: 2018-06-21 Advisory first published on website: 2018-06-22 Advisory sent to Bugtraq mailing list: 2018 ...
reSIProcate version 1102 suffers from a heap overflow vulnerability ...