CVE-2016-10324: Buffer Overflow
Published Apr 13, 2017
·Updated
In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osipclrncpy() function defined in osipparser2/osipport.c.
Affected Software
1 affected component
GNU osip=4.1.0
Remediation
Patch Available
Event History
Apr 13, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10324?
CVE-2016-10324 has a high severity rating due to the potential for a heap buffer overflow that can be exploited by attackers.
2
How do I fix CVE-2016-10324?
To fix CVE-2016-10324, update the GNU oSIP software to a version later than 4.1.0 that addresses this vulnerability.
3
What types of attacks can CVE-2016-10324 facilitate?
CVE-2016-10324 can facilitate remote code execution attacks through crafted SIP messages.
4
Which versions of GNU oSIP are affected by CVE-2016-10324?
CVE-2016-10324 affects GNU oSIP version 4.1.0.
5
Is CVE-2016-10324 easy to exploit?
Yes, CVE-2016-10324 can be exploited easily if an attacker can send malformed SIP messages to a vulnerable system.