PT-2017-12151 · Sipcrack+1 · Sipcrack+1

CVE-2017-11654

·

Publicado

2017-07-26

·

Atualizado

2022-10-06

CVSS v3.1

5.9

Média

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions SIPcrack version 0.2
Description An out-of-bounds read and write flaw was found in the way SIPcrack processed SIP traffic, due to mishandling of 0x00 termination of a payload array. A remote attacker could potentially use this flaw to crash the sipdump process by generating specially crafted SIP traffic.
Recommendations For SIPcrack version 0.2, consider restricting access to the sipdump process until a patch is available to prevent potential crashes caused by specially crafted SIP traffic.

Exploit

Correção

Memory Corruption

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-11654

Produtos afetados

Debian
Sipcrack