CVE-2017-11654: Sipcrack Project Sipcrack

Medium severity, CVSS 5.9. EPSS: 2% chance of exploitation in the next 30 days.

An out-of-bounds read and write flaw was found in the way SIPcrack 0.2 processed SIP traffic, because 0x00 termination of a payload array was mishandled. A remote attacker could potentially use this flaw to crash the sipdump process by generating specially crafted SIP traffic.

Affected products

Published 2017-07-26. Last modified 2026-06-17.