SIPP 3.3 contains a stack-based buffer overflow...
High severity
Unreviewed
Published
Mar 28, 2026
to the GitHub Advisory Database
•
Updated Mar 28, 2026
Description
Published by the National Vulnerability Database
Mar 28, 2026
Published to the GitHub Advisory Database
Mar 28, 2026
Last updated
Mar 28, 2026
SIPP 3.3 contains a stack-based buffer overflow vulnerability that allows local unauthenticated attackers to execute arbitrary code by supplying malicious input in the configuration file. Attackers can craft a configuration file with oversized values that overflow a stack buffer, overwriting the return address and executing arbitrary code through return-oriented programming gadgets.
References