Vulnerability in Linphone SIP Stack Could Allow Attackers to Remotely Crash Client Devices
On September 1, 2021, cybersecurity researchers revealed a zero-click vulnerability in the Linphone Session Initiation Protocol (SIP) stack. This flaw can be exploited remotely to crash the SIP client without any action needed from the victim, leading to a denial-of-service (DoS) condition. Identified as CVE-2021-33056 (with a CVSS score of 7.5), it arises from a NULL pointer dereference in the “belle-sip” component, a C-language library that supports SIP transport, transactions, and dialog layers. All versions prior to 4.5.20 are affected. The vulnerability was discovered and reported by the cybersecurity company Claroty. Linphone is an open-source, cross-platform SIP client that facilitates voice and video calls, end-to-end encrypted messaging, and audio conferences. SIP is the signaling protocol used to initiate, maintain, and terminate real-time multimedia communication sessions.
Linphone SIP Stack Vulnerability Exposes Clients to Remote Disruption On September 1, 2021, cybersecurity experts unveiled a critical zero-click vulnerability within the Linphone Session Initiation Protocol (SIP) stack, allowing potential exploitation that could lead to remote crashes of affected client devices. Identified as CVE-2021-33056, this vulnerability boasts a CVSS score…
Vulnerability in Linphone SIP Stack Could Allow Attackers to Remotely Crash Client Devices
On September 1, 2021, cybersecurity researchers revealed a zero-click vulnerability in the Linphone Session Initiation Protocol (SIP) stack. This flaw can be exploited remotely to crash the SIP client without any action needed from the victim, leading to a denial-of-service (DoS) condition. Identified as CVE-2021-33056 (with a CVSS score of 7.5), it arises from a NULL pointer dereference in the “belle-sip” component, a C-language library that supports SIP transport, transactions, and dialog layers. All versions prior to 4.5.20 are affected. The vulnerability was discovered and reported by the cybersecurity company Claroty. Linphone is an open-source, cross-platform SIP client that facilitates voice and video calls, end-to-end encrypted messaging, and audio conferences. SIP is the signaling protocol used to initiate, maintain, and terminate real-time multimedia communication sessions.