<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>SIPp (&lt;= 3.7.7) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/sipp--3.7.7/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 13 Sep 2026 13:25:48 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/sipp--3.7.7/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Buffer Overflow Vulnerability in SIPp get_peer_tag()</title><link>https://feed.craftedsignal.io/briefs/2026-09-sipp-buffer-overflow/</link><pubDate>Sun, 13 Sep 2026 13:25:48 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-sipp-buffer-overflow/</guid><description>SIPp versions 3.7.7 and earlier contain a buffer overflow vulnerability in the get_peer_tag() function that allows remote attackers to cause a denial of service.</description><content:encoded><![CDATA[<p>SIPp versions 3.7.7 and earlier are vulnerable to a stack-based buffer overflow within the get_peer_tag() function. The vulnerability occurs during the processing of incoming SIP messages when a 'To' header contains a tag parameter exceeding 2048 bytes. An unauthenticated remote attacker can exploit this flaw by sending a specifically crafted SIP message to a listening SIPp instance. Successful exploitation results in the corruption of the stack memory, causing the SIPp process to crash, thereby leading to a denial-of-service condition. Because SIPp is frequently used in telecommunications infrastructure for load testing and stress testing, such a crash can cause significant service disruption in testing environments.</p>
<h2 id="impact">Impact</h2>
<p>The primary impact of this vulnerability is a denial-of-service condition where the SIPp service becomes unavailable due to process termination. This vulnerability affects users of SIPp 3.7.7 and earlier across all platforms. Organizations relying on SIPp for network performance validation or protocol testing are at risk of unexpected service outages if exposed to malicious SIP traffic.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Update all instances of SIPp to a version later than 3.7.7. As the maintainers have not yet provided a fixed release in the source, monitor the official SIPp repository for patch releases addressing CVE-2026-90778. In the interim, implement ingress filtering or deep packet inspection on SIP traffic to identify and drop packets containing 'To' header tag parameters with lengths exceeding 2048 bytes.</p>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category><category>vulnerability</category><category>denial-of-service</category><category>network-protocol</category></item></channel></rss>