The Session Initiation Protocol (SIP) implementation in IPTel SIP Express Router 0.8.9 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.
https://exchange.xforce.ibmcloud.com/vulnerabilities/11379
http://www.securityfocus.com/bid/6904
http://www.kb.cert.org/vuls/id/528719