Multiple stack-based buffer overflows in the (1) getremoteipmedia and (2) getremoteipv6media functions in call.cpp in SIPp 3.1 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted SIP message.