CVE-2017-11654: Sipcrack Project Sipcrack
Medium severity, CVSS 5.9. EPSS: 2% chance of exploitation in the next 30 days.
An out-of-bounds read and write flaw was found in the way SIPcrack 0.2 processed SIP traffic, because 0x00 termination of a payload array was mishandled. A remote attacker could potentially use this flaw to crash the sipdump process by generating specially crafted SIP traffic.
Affected products
- Sipcrack Project Sipcrack: version 0.2 only
Published 2017-07-26. Last modified 2026-06-17.