Exploitation Summary
EIP tracks 1 public exploit for CVE-2018-12584. PoCs published by Joachim De Zutter.
AI-analyzed exploit summary This Python script exploits a heap overflow vulnerability in reSIProcate SIP stack (CVE-2018-12584) by sending maliciously crafted SIP messages over TLS with mismatched Content-Length headers. It can trigger the vulnerability in both client and server modes, potentially leading to remote code execution.
Description
The ConnectionBase::preparseNewBytes function in resip/stack/ConnectionBase.cxx in reSIProcate through 1.10.2 allows remote attackers to cause a denial of service (buffer overflow) or possibly execute arbitrary code when TLS communication is enabled.
Exploits (1)
This Python script exploits a heap overflow vulnerability in reSIProcate SIP stack (CVE-2018-12584) by sending maliciously crafted SIP messages over TLS with mismatched Content-Length headers. It can trigger the vulnerability in both client and server modes, potentially leading to remote code execution.
References (7)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H