SIPSorcery is vulnerable to Denial of Service (DoS)
75
High Risk
SctpSackChunk.ParseChunk reads the gap-ack-block and duplicate-TSN counts directly from an externally supplied SCTP SACK chunk and loops that many times without validating the counts against the chunk length or the receive buffer size. A crafted SACK chunk reads past the end of the fixed-size receive buffer, raising an out-of-bounds exception that the recoverable handler does not catch. The dedicated SCTP receive thread then exits with no restart. The fix validates the declared counts against the chunk bounds before iterating.
You are affected if you are using a version that falls within the vulnerable range and you process SCTP traffic over WebRTC data channels or SCTP-over-UDP.
SIPSorcery is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 10.0.13.
Upgrade the SIPSorcery library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant