{"id":"CVE-2018-12584","details":"The ConnectionBase::preparseNewBytes function in resip/stack/ConnectionBase.cxx in reSIProcate through 1.10.2 allows remote attackers to cause a denial of service (buffer overflow) or possibly execute arbitrary code when TLS communication is enabled.","modified":"2026-07-08T17:57:26.412444Z","published":"2018-07-16T20:29:00.487Z","database_specific":{"unresolved_ranges":[{"extracted_events":[{"introduced":"8.0"},{"last_affected":"8.0"},{"introduced":"9.0"},{"last_affected":"9.0"}],"source":"CPE_STRING","vendor_product":"debian:debian_linux","cpes":["cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"]}]},"references":[{"type":"ADVISORY","url":"http://joachimdezutter.webredirect.org/advisory.html"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2018/07/msg00031.html"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2021/12/msg00029.html"},{"type":"FIX","url":"http://seclists.org/bugtraq/2018/Aug/14"},{"type":"FIX","url":"https://github.com/resiprocate/resiprocate/commit/2cb291191c93c7c4e371e22cb89805a5b31d6608"},{"type":"FIX","url":"https://packetstormsecurity.com/files/148856/reSIProcate-1.10.2-Heap-Overflow.html"},{"type":"FIX","url":"https://www.exploit-db.com/exploits/45174/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/resiprocate/resiprocate","events":[{"introduced":"0"},{"last_affected":"dd6e415b5abccc6ed78958837e1730ba72733a91"},{"fixed":"2cb291191c93c7c4e371e22cb89805a5b31d6608"}],"database_specific":{"cpe":"cpe:2.3:a:resiprocate:resiprocate:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"1.10.2"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["resiprocate-1.11.0_beta2","resiprocate-1.11.0_beta1","resiprocate-1.11.0_alpha11","resiprocate-1.11.0_alpha10","resiprocate-1.11.0_alpha9","resiprocate-1.11.0_alpha8","resiprocate-1.11.0_alpha7","resiprocate-1.11.0_alpha6","resiprocate-1.11.0_alpha5","resiprocate-1.11.0_alpha4","resiprocate-1.11.0_alpha3","resiprocate-1.11.0_alpha2","resiprocate-1.11.0_alpha1","resiprocate-1.10.2","resiprocate-1.10.1","resiprocate-1.10.0","resiprocate-1.10.0_beta2","resiprocate-1.10.0_beta1","resiprocate-1.10.0_alpha4","resiprocate-1.10.0_alpha3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-12584.json","vanir_signatures_modified":"2026-07-08T17:57:26Z","vanir_signatures":[{"id":"CVE-2018-12584-1f61868f","signature_type":"Line","signature_version":"v1","source":"https://github.com/resiprocate/resiprocate/commit/2cb291191c93c7c4e371e22cb89805a5b31d6608","target":{"file":"resip/stack/ConnectionBase.cxx"},"deprecated":false,"digest":{"line_hashes":["178007103552507550579810376132377140385","173992908705831645411808277503224922305","50554873215173466783289028907298373026","98168916845416611335407520653460520446","74814719768476633761236422036907966049","85034238564629132549601043780386375497","132171870175668759357258859621412560200","117434914664648003928238649723361089808","232812770327501620566202059740027415932","226851229450964725983602165267031443005","39761695400498134734070570780654339565","262377287743590938540800189458590266101","84809140518011335890828229181535224530","313034784951355725028364086318449601377","248522007255775402721843824164126429923","20886035095101740777309533583067574114","76389818129287673917936469876338961422","10011605700828042744260629277411451287","80441884412579238464548431153228920050"],"threshold":0.9}},{"signature_version":"v1","source":"https://github.com/resiprocate/resiprocate/commit/2cb291191c93c7c4e371e22cb89805a5b31d6608","target":{"file":"resip/stack/ConnectionBase.cxx","function":"ConnectionBase::preparseNewBytes"},"deprecated":false,"digest":{"function_hash":"100331230615351000510461227701829668167","length":7206},"id":"CVE-2018-12584-30592e15","signature_type":"Function"}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}