An issue was discovered in the libsofia-sip fork in...
High severity
Unreviewed
Published
Dec 18, 2022
to the GitHub Advisory Database
•
Updated Apr 17, 2025
Description
Published by the National Vulnerability Database
Dec 18, 2022
Published to the GitHub Advisory Database
Dec 18, 2022
Last updated
Apr 17, 2025
An issue was discovered in the libsofia-sip fork in drachtio-server before 0.8.19. It allows remote attackers to cause a denial of service (daemon crash) via a crafted UDP message that causes a url_canonize2 heap-based buffer over-read because of an off-by-one error.
References