CVE-2017-7853: Buffer Overflow
Published Apr 13, 2017
·Updated
In libosip2 in GNU oSIP 4.1.0 and 5.0.0, a malformed SIP message can lead to a heap buffer overflow in the msgosipbodyparse() function defined in osipparser2/osipmessageparse.c, resulting in a remote DoS.
Affected Software
1 affected component
GNU osip=5.0.0
Remediation
Patch Available
Event History
Apr 13, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·04:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-7853?
CVE-2017-7853 has a high severity rating due to its potential for remote denial of service attacks caused by heap buffer overflow.
2
How do I fix CVE-2017-7853?
The recommended fix for CVE-2017-7853 is to upgrade to a patched version of GNU oSIP that addresses the vulnerability.
3
Which versions of GNU oSIP are affected by CVE-2017-7853?
CVE-2017-7853 affects GNU oSIP versions 4.1.0 and 5.0.0.
4
What type of attack is associated with CVE-2017-7853?
CVE-2017-7853 is associated with denial of service attacks due to vulnerabilities in SIP message parsing.
5
What component of GNU oSIP is vulnerable in CVE-2017-7853?
CVE-2017-7853 affects the msg_osip_body_parse() function in the libosip2 library.