sipclient.cpp in KPhone 4.0.1 and earlier allows remote attackers to cause a denial of service (crash) via a STUN response packet with a large attrLen value that causes an out-of-bounds read.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.129
EPSS Ranking 93.8%