Impact
A stack-based buffer overflow occurs when OpenSIPS copies an oversized watcher URI into a fixed-size buffer during watcherinfo XML generation. The flaw allows an attacker to crash the worker process, resulting in a denial of service. The vulnerability is triggered by a malformed SUBSCRIBE Event: presence request containing a long From URI.
Affected Systems
The affected vendor is OpenSIPS. Versions before 3.6.6 and before 4.0.0‑rc1 are vulnerable. The issue requires that both the presence and presence_xml modules be loaded and that SUBSCRIBE routing be reachable.
Risk and Exploitability
The CVSS score of 8.7 categorises the flaw as high severity. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the flaw remotely by sending a crafted SIP SUBSCRIBE containing an excessively long From URI, causing the worker process to crash. In deployments where the presence modules are enabled, this leads to service disruption.
OpenCVE Enrichment