Crashing SIP Clients with a Single Slash | Team82
ID: 0fc990c9-e33c-57e4-9b8e-04a3976d5f4d
STIX ID: report--0fc990c9-e33c-57e4-9b8e-04a3976d5f4d
Feed Name: Claroty Team82
Threat Score
Team82 disclosed CVE-2021-33056: a remotely exploitable NULL pointer dereference in the belle-sip SIP parsing library used by Linphone and many SIP-based/IoT products. Sending a crafted From/To/Diversion header (for example a header value of "/") can trigger a crash (denial-of-service) with zero user interaction; the issue affects belle-sip versions prior to v4.5.20 and was fixed in v4.5.20, so affected vendors and devices should apply the update downstream.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
