VYPR

Sipcrack

by Sipcrack Project

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2017-11655Hig0.497.50.02Jul 26, 2017A memory leak was found in the way SIPcrack 0.2 handled processing of SIP traffic, because a lines array was mismanaged. A remote attacker could potentially use this flaw to crash long-running sipdump network sniffing sessions.
CVE-2017-11654Med0.385.90.01Jul 26, 2017An out-of-bounds read and write flaw was found in the way SIPcrack 0.2 processed SIP traffic, because 0x00 termination of a payload array was mishandled. A remote attacker could potentially use this flaw to crash the sipdump process by generating specially crafted SIP traffic.