CVE-2008-2085
EPSS 3.7%
Description
Multiple stack-based buffer overflows in the (1) get_remote_ip_media and (2) get_remote_ipv6_media functions in call.cpp in SIPp 3.1 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted SIP message.
How to fix CVE-2008-2085
To remediate CVE-2008-2085, upgrade the affected package to a fixed version below.
- Debian/sip-tester—upgrade to 2.0.1-1.2 or later
Is CVE-2008-2085 being exploited?
Low — EPSS is 3.7%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.0.1-1.2