VYPR
High severity7.5NVD Advisory· Published Sep 13, 2026

CVE-2026-90779

CVE-2026-90779

Description

SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authentication challenges with oversized algorithm parameters. A malicious SIP server can send a crafted 401 or 407 challenge to corrupt the stack and crash the client process.

Affected products

2
  • Sipp/Sippreferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <3.7.7

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.