CVE-2016-10326: Buffer Overflow
Published Apr 13, 2017
·Updated
In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osipbodytostr() function defined in osipparser2/osipbody.c, resulting in a remote DoS.
Affected Software
1 affected component
GNU osip=4.1.0
Remediation
Patch Available
Event History
Apr 13, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10326?
CVE-2016-10326 has a high severity due to its potential to cause a remote denial of service (DoS) through a heap buffer overflow.
2
How do I fix CVE-2016-10326?
To fix CVE-2016-10326, upgrade to a patched version of GNU oSIP that addresses this vulnerability.
3
What software is affected by CVE-2016-10326?
CVE-2016-10326 affects GNU oSIP version 4.1.0.
4
What type of vulnerability is CVE-2016-10326?
CVE-2016-10326 is a heap buffer overflow vulnerability caused by malformed SIP messages.
5
Can CVE-2016-10326 be exploited remotely?
Yes, CVE-2016-10326 can be exploited remotely, leading to a denial of service condition.