AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-13T12:17:17.093Z and has not been modified since then. The vulnerability is a buffer overflow in SIPp through 3.7.7, which can be exploited by unauthenticated remote attackers to crash the process. Defenders should prioritize verifying exposure, applying patches, and monitoring for suspicious activi [truncated]
A stack buffer overflow vulnerability exists in SIPp through version 3.7.7 in the createAuthHeader() function when processing SIP authentication challenges with oversized algorithm parameters. A malicious SIP server can send a crafted 401 or 407 challenge to corrupt the stack and crash the client process. This vulnerability can lead to service disruptions in SIPp installations. SIPp users and administrato [truncated]
CVE-2026-90778 is a buffer overflow vulnerability in the get_peer_tag() function of SIPp, a SIP testing tool, through version 3.7.7. The vulnerability occurs when processing SIP To headers with tag parameters of 2049 bytes or more. Unauthenticated remote attackers can exploit this by sending crafted SIP messages with oversized tag parameters, causing a buffer overflow and crashing the process. This issue [truncated]
A local buffer overflow vulnerability exists in SIPp 3.6 and earlier versions, affecting command-line argument handling. The flaw resides in sipp.cpp where strcpy operations on the -3pcc, -i, and -log_file parameters lack proper bounds checking, allowing oversized input to write beyond allocated buffer boundaries. This vulnerability enables local attackers to crash the application or potentially execute a [truncated]