A NULL pointer dereference vulnerability exists in eXcall_api.c in Antisip eXosip2 through 5.2.0 when handling certain 3xx redirect responses.
The product dereferences a pointer that it expects to be valid but is NULL.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Exosip2 | Antisip | * | 5.2.0 (including) | 
| Libexosip2 | Ubuntu | bionic | * | 
| Libexosip2 | Ubuntu | trusty | * | 
| Libexosip2 | Ubuntu | upstream | * | 
| Libexosip2 | Ubuntu | xenial | * |