vendor:
SIPp
by:
Nawaf Alkeraithe
7.8
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: SIPp
Affected Version From: 3.3.990
Affected Version To: 3.3.990
Patch Exists: YES
Related CWE: N/A
CPE: a:sipp:sipp
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux
2018
SIPp 3.3.990 – Local Buffer Overflow (PoC)
SIPp 3.3.990 is vulnerable to a local buffer overflow vulnerability. An attacker can exploit this vulnerability by providing a large string of 'A's as an argument to the -trace_logs, -message_file, -calldebug_file, and -trace_err options. This will cause a segmentation fault and crash the application.
Mitigation:
Upgrade to the latest version of SIPp.