CVE-2014-10375: GNU Exosip

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

handle_messages in eXtl_tls.c in eXosip before 5.0.0 mishandles a negative value in a content-length header.

Affected products

  • GNU Exosip: before 5.0.0 (fixed in 5.0.0)

Published 2019-08-14. Last modified 2026-06-17.