<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Sip - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/sip/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 12 Sep 2026 19:21:24 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/sip/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stack-based Buffer Overflow in sngrep SIP Parsing</title><link>https://feed.craftedsignal.io/briefs/2026-09-sngrep-buffer-overflow/</link><pubDate>Sat, 12 Sep 2026 19:21:24 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-sngrep-buffer-overflow/</guid><description>sngrep versions up to 1.8.4 are vulnerable to a stack-based buffer overflow in SIP header formatting routines, allowing attackers to trigger crashes or achieve remote code execution via malformed SIP packets.</description><content:encoded><![CDATA[<p>sngrep versions 1.8.4 and earlier contain a critical stack-based buffer overflow vulnerability (CVE-2026-90558) within its SIP attribute formatting routines. The vulnerability arises from inadequate boundary checks when parsing SIP headers, such as Call-ID or X-Call-ID, which are constrained to a 255-byte stack buffer. When an attacker sends a specially crafted SIP packet containing header values exceeding this limit, the application memory is corrupted during the rendering process. This flaw enables attackers to force a process crash, leading to a denial-of-service, or potentially overwrite return addresses to execute arbitrary code with the privileges of the sngrep process. Given that sngrep is frequently used in network monitoring environments to capture and analyze VoIP traffic, successful exploitation could facilitate remote code execution on sensitive network management infrastructure.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows for remote code execution or application crashes. This impacts network security and VoIP service providers utilizing sngrep for traffic analysis. If an attacker gains code execution, they could achieve persistence within the monitoring node, sniff additional traffic, or pivot into other network segments where the monitoring node is located.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the update of all sngrep installations to a version beyond 1.8.4 that includes the fix for CVE-2026-90558. Implement network-level ingress filtering to prevent unauthorized SIP traffic from reaching network monitoring infrastructure that is not intended to be exposed to external actors.</p>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>vulnerability</category><category>rce</category><category>sip</category><category>networking</category></item></channel></rss>