CVE-2018-12584
The ConnectionBase::preparseNewBytes function in resip/stack/ConnectionBase.cxx in reSIProcate through 1.10.2 allows remote attackers to cause a denial of service (buffer overflow) or possibly execute arbitrary code when TLS communication is enabled.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 24.6%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
The ConnectionBase::preparseNewBytes function in resip/stack/ConnectionBase.cxx in reSIProcate through 1.10.2 allows remote attackers to cause a denial of service (buffer overflow) or possibly execute arbitrary code when TLS communication is enabled.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 24.59% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-120
- Affected
- resiprocate/resiprocate · debian/debian linux
- Source
- cve@mitre.org
References
- http://joachimdezutter.webredirect.org/advisory.htmlBroken Link
- http://seclists.org/bugtraq/2018/Aug/14Exploit, Mailing List, Patch, Third Party Advisory
- https://github.com/resiprocate/resiprocate/commit/2cb291191c93c7c4e371e22cb89805a5b31d6608Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/07/msg00031.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/12/msg00029.htmlMailing List, Third Party Advisory
- https://packetstormsecurity.com/files/148856/reSIProcate-1.10.2-Heap-Overflow.htmlExploit, Patch, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/45174/Exploit, Patch, Third Party Advisory, VDB Entry
- http://joachimdezutter.webredirect.org/advisory.htmlBroken Link
- http://seclists.org/bugtraq/2018/Aug/14Exploit, Mailing List, Patch, Third Party Advisory
- https://github.com/resiprocate/resiprocate/commit/2cb291191c93c7c4e371e22cb89805a5b31d6608Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/07/msg00031.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/12/msg00029.htmlMailing List, Third Party Advisory
- https://packetstormsecurity.com/files/148856/reSIProcate-1.10.2-Heap-Overflow.htmlExploit, Patch, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/45174/Exploit, Patch, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.