[reSIProcate] [CVE-2018-12584] Heap overflow vulnerability in resiprocate through 1.10.2

Joachim De Zutter dezutterjoachim at gmail.com
Mon Aug 20 03:27:06 CDT 2018


 A heap overflow vulnerability which might lead to a DoS or remote code
execution in client and server software using the reSIProcate sip stack has
been found. (CVE-2018-12584)

Full advisory: http://joachimdezutter.webredirect.org/advisory.html

The issue has been fixed since this commit:

https://github.com/resiprocate/resiprocate/commit/2cb291191c93c7c4e371e22cb89805a5b31d6608

Please update your software if you haven't done so already.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://list.resiprocate.org/pipermail/resiprocate-devel/attachments/20180820/26f11595/attachment.htm>


More information about the resiprocate-devel mailing list