NULL Pointer Dereference
CVE-2025-68274
Summary
SIPGO is a library for writing SIP services in the GO language. In versions from 0.3.0 prior to 1.0.0-alpha-1, a Nil Pointer Dereference vulnerability is present in the SIPGO library's "NewResponseFromRequest()" function that affects all normal SIP operations. The vulnerability allows remote attackers to crash any SIP application by sending a single malformed SIP request without a "To" header. The vulnerability occurs when SIP message parsing succeeds for a request missing the "To" header, but the response creation code assumes the "To" header exists without proper nil checks. This affects routine operations like call setup, authentication, and message handling - not just error cases. This vulnerability affects all SIP applications using the sipgo library, not just specific configurations or edge cases, as long as they make use of the "NewResponseFromRequest()" function.
- LOW
- NETWORK
- NONE
- UNCHANGED
- NONE
- NONE
- NONE
- HIGH
CWE-476 - NULL Pointer Dereference
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Advisory Timeline
- Published