GNU oSIP v5.3.0 was discovered to contain an integer overflow via the component osipbodyparseheader.
In libosip2 in GNU oSIP 4.1.0 and 5.0.0, a malformed SIP message can lead to a heap buffer overflow in the msgosipbodyparse() function defined in osipparser2/osipmessageparse.c, resulting in a remote DoS.
In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osipmessagetostr() function defined in osipparser2/osipmessagetostr.c, resulting in a remote DoS.
In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osipclrncpy() function defined in osipparser2/osipport.c.
In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osipbodytostr() function defined in osipparser2/osipbody.c, resulting in a remote DoS.