CVE-2022-41550

CWE-190Integer Overflow5 documents5 sources
Severity
6.5MEDIUM
EPSS
0.2%
top 54.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 11
Latest updateOct 12

Description

GNU oSIP v5.3.0 was discovered to contain an integer overflow via the component osip_body_parse_header.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

Debianlibosip2< 5.3.0-2.1+2
NVDgnu/osip5.3.0

🔴Vulnerability Details

3
GHSA
GHSA-rmjm-5vpx-phrf: GNU oSIP v52022-10-12
OSV
CVE-2022-41550: GNU oSIP v52022-10-11
CVEList
CVE-2022-41550: GNU oSIP v52022-10-11

📋Vendor Advisories

1
Debian
CVE-2022-41550: libosip2 - GNU oSIP v5.3.0 was discovered to contain an integer overflow via the component ...2022