CVE-2016-10325: Buffer Overflow
Published Apr 13, 2017
·Updated
In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osipmessagetostr() function defined in osipparser2/osipmessagetostr.c, resulting in a remote DoS.
Affected Software
1 affected component
GNU osip=4.1.0
Remediation
Patch Available
Event History
Apr 13, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10325?
CVE-2016-10325 has a high severity rating due to the potential for remote denial of service (DoS) attacks.
2
How does CVE-2016-10325 affect GNU oSIP 4.1.0?
CVE-2016-10325 affects GNU oSIP 4.1.0 by allowing malformed SIP messages to cause a heap buffer overflow.
3
What are the potential impacts of CVE-2016-10325?
The potential impacts of CVE-2016-10325 include system crashes and denial of service for applications using GNU oSIP.
4
How do I fix CVE-2016-10325?
To fix CVE-2016-10325, you should upgrade to a patched version of GNU oSIP that resolves this vulnerability.
5
Is CVE-2016-10325 exploitable remotely?
Yes, CVE-2016-10325 is exploitable remotely through specially crafted SIP messages.