CVE-2018-25225: SIPP 3.3 Stack-Based Buffer Overflow via Configuration File
SIPP 3.3 contains a stack-based buffer overflow vulnerability that allows local unauthenticated attackers to execute arbitrary code by supplying malicious input in the configuration file. Attackers can craft a configuration file with oversized values that overflow a stack buffer, overwriting the return address and executing arbitrary code through return-oriented programming gadgets.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-25225?
CVE-2018-25225 has a high severity rating due to the potential for local unauthenticated attackers to execute arbitrary code.
How do I fix CVE-2018-25225?
To remediate CVE-2018-25225, update to the latest version of SIPp that addresses the buffer overflow vulnerability.
Who is affected by CVE-2018-25225?
CVE-2018-25225 affects users of SIPp version 3.3.
What can attackers achieve with CVE-2018-25225?
Attackers exploiting CVE-2018-25225 can potentially execute arbitrary code on the affected system.
Is CVE-2018-25225 a network vulnerability?
CVE-2018-25225 is not a network vulnerability; it is a local vulnerability that requires access to the configuration file.