vendor:
reSIProcate
by:
MUDynamics
7.5
CVSS
HIGH
Remote DoS
119
CWE
Product Name: reSIProcate
Affected Version From: 1.3.2002
Affected Version To: 1.3.2002
Patch Exists: YES
Related CWE: N/A
CPE: a:resiprocate:resiprocate:1.3.2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
Remote DoS in reSIProcate [MU-200807-01]
A malformed INVITE or OPTIONS message to the repro SIP proxy/registrar can crash the process. The crash is caused by an assertion failure that occurs when the domain name in the request line URI is too long (rutil/dns/DnsStub.cxx, line 493). For example, the URI may be 'sip:bob@example.comAAAAAAA...', where 'sip:bob@example.com' is followed by 256 As.
Mitigation:
Update to 1.3.3, available from https://www.resiprocate.org/files/pub/reSIProcate/releases/