Security Advisory

CVE-2026-90779

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-13 11:42:28
Last updated 2026-09-14 15:34:22
Assigner VulnCheck
CVSS score 8.7
State PUBLISHED

Description

SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authentication challenges with oversized algorithm parameters. A malicious SIP server can send a crafted 401 or 407 challenge to corrupt the stack and crash the client process.