HIGH
SIPP 3.3 Stack-Based Buffer Overflow via Configuration File
Published Mar 28, 2026
8.6
HIGHCVSS 4.0
EPSS 0.19%
Description
SIPP 3.3 contains a stack-based buffer overflow vulnerability that allows local unauthenticated attackers to execute arbitrary code by supplying malicious input in the configuration file. Attackers can craft a configuration file with oversized values that overflow a stack buffer, overwriting the return address and executing arbitrary code through return-oriented programming gadgets.
Affected products
-
- Version 3.3StatusaffectedConstraints-
- Version
- 3.3
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- http://sipp.sourceforge.net/ product
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-21708 Advisory
- https://www.exploit-db.com/exploits/45288 exploitVDB Entry
- https://www.vulncheck.com/advisories/sipp-stack-based-buffer-overflow-via-configuration-file third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://sipp.sourceforge.net/ | product | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-21708 | Advisory | |
| https://www.exploit-db.com/exploits/45288 | exploitVDB Entry | |
| https://www.vulncheck.com/advisories/sipp-stack-based-buffer-overflow-via-configuration-file | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Mar 28, 2026
Updated Mar 30, 2026
Reserved Mar 28, 2026
Link CVE-2018-25225
CISA Vulnrichment
Updated Mar 30, 2026
ENISA EUVD
EUVD-2018-21708 Assigner VulnCheck
Published Mar 28, 2026
Updated Mar 30, 2026
Exploited since n/a
Link EUVD-2018-21708