sipp vulnerability

SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authentication challenges with oversized algorithm parameters. A malicious SIP server can send a crafted 401 or 407 challenge to corrupt the stack and crash the client process.

Published 13 Sep 2026Updated 13 Sep 20265 sources
CVSS 8.7

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.