SIPp 3.7.7 及更早版本在 函数中处理 SIP 认证质询时,若认证质询中的算法参数过大,会触发栈缓冲区溢出漏洞。攻击者可通过恶意构造的 SIP 服务器发送特制的 401 或 407 认证质询,导致栈内存被破坏,从而引发客户端进程崩溃。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90780 | 7.5 HIGH | SIPp through 3.7.7 Buffer Overflow via Oversized SIP Header Content |
| CVE-2026-90778 | 7.5 HIGH | SIPp through 3.7.7 Buffer Overflow via SIP To Header Tag |
No comments yet