PT-2024-23843 · Sngrep+2 · Sngrep+2

Htejeda

·

Published

2024-04-09

·

Updated

2025-04-11

·

CVE-2024-3120

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions sngrep versions 1.4.1 and later
Description A stack-buffer overflow issue exists due to inadequate bounds checking when copying Content-Length and Warning headers into fixed-size buffers in the sip validate packet and sip parse extra headers functions within src/sip.c. This allows remote attackers to execute arbitrary code or cause a denial of service (DoS) via crafted SIP messages.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

RCE

Memory Corruption

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2025-5216
CVE-2024-3120
OPENSUSE-SU-2024:0106-1
OPENSUSE-SU-2024:13856-1

Affected Products

Alt Linux
Debian
Sngrep