In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osipclrncpy() function defined in osipparser2/osipport.c (CVE-2016-10324).
In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osipmessagetostr() function defined in osipparser2/osipmessageto_str.c, resulting in a remote DoS (CVE-2016-10325).
In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osipbodytostr() function defined in osipparser2/osipbody.c, resulting in a remote DoS (CVE-2016-10326).
In libosip2 in GNU 5.0.0, a malformed SIP message can lead to a heap buffer overflow in the msgosipbodyparse() function defined in osipparser2/osipmessage_parse.c, resulting in a remote DoS (CVE-2017-7853).