Vulnerabilidad · Publicado 13/09/2026
SIPp versiones hasta 3.7.7 contiene un desbordamiento de búfer en la función get_header() que permite a atacantes no autenticados enviar mensajes SIP con encabezados superiores a 20,490 bytes para causar crasheo del proceso. Esta vulnerabilidad afecta servidores VoIP y sistemas de prueba de telefonía en infraestructuras empresariales de LATAM. El impacto incluye negación de servicio en infraestructuras de comunicaciones altas.
SIPp through 3.7.7 contains a buffer overflow vulnerability in the get_header() function in src/sip_parser.cpp when processing SIP messages with header content exceeding 20,490 bytes. Unauthenticated remote attackers can send crafted SIP messages with oversized headers to overflow the static buffer and crash the process.
Score: 7.5/10 — Severidad: HIGH — Estado NIST: Received
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-120
Publicado en NIST NVD.