ZoIPer 2.22, and possibly other versions before 2.24 Library 5324, allows remote attackers to cause a denial of service (crash) via a SIP INVITE request with an empty Call-Info header.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Zoiper | Zoiper | * | 2.22 (including) |
Zoiper | Zoiper | 2.0 (including) | 2.0 (including) |
Zoiper | Zoiper | 2.10 (including) | 2.10 (including) |
Zoiper | Zoiper | 2.11 (including) | 2.11 (including) |