CVE-2024-35434: Buffer Overflow
Published May 29, 2024
·Updated
Irontec Sngrep v1.8.1 was discovered to contain a heap buffer overflow via the function rtpcheckpacket at /sngrep/src/rtp.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SIP packet.
Affected Software
2 affected components
Irontec Sngrep
Irontec Sngrep=1.8.1
Remediation
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 29, 2024
CVE Published
via NVD·07:15 PM
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Aug 22, 2024
Data Sourced
via MITRE·07:54 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-35434?
CVE-2024-35434 is classified as a high-severity vulnerability due to its potential to cause Denial of Service.
2
How do I fix CVE-2024-35434?
To fix CVE-2024-35434, upgrade to the latest version of Irontec Sngrep that addresses the heap buffer overflow.
3
What type of attack does CVE-2024-35434 facilitate?
CVE-2024-35434 can facilitate a Denial of Service (DoS) attack through a crafted SIP packet.
4
Which function is affected in CVE-2024-35434?
The function affected in CVE-2024-35434 is rtp_check_packet located in the /sngrep/src/rtp.c file.
5
What software is impacted by CVE-2024-35434?
CVE-2024-35434 impacts Irontec Sngrep version 1.8.1.