A NULL pointer dereference vulnerability exists in eXcall_api.c in Antisip eXosip2 through 5.2.0 when handling certain 3xx redirect responses.
The product dereferences a pointer that it expects to be valid but is NULL.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Exosip2 | Antisip | * | 5.2.0 (including) |
Libexosip2 | Ubuntu | bionic | * |
Libexosip2 | Ubuntu | trusty | * |
Libexosip2 | Ubuntu | upstream | * |
Libexosip2 | Ubuntu | xenial | * |