The Open Phone Abstraction Library (opal), as used by (1)...
Vulnerability Description
The Open Phone Abstraction Library (opal), as used by (1) Ekiga before 2.0.10 and (2) OpenH323 before 2.2.4, allows remote attackers to cause a denial of service (crash) via an invalid Content-Length header field in Session Initiation Protocol (SIP) packets, which causes a \0 byte to be written to an "attacker-controlled address."
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-4924
Credits & Attribution
No credits recorded in the NVD database.
References
- http://secunia.com/advisories/27118
- http://secunia.com/advisories/27271
- http://www.securitytracker.com/id?1018776
- http://www.securityfocus.com/bid/25955
- http://secunia.com/advisories/27129
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:205
- https://bugzilla.redhat.com/show_bug.cgi?id=296371
- http://secunia.com/advisories/28380
- http://osvdb.org/41637
- http://www.redhat.com/support/errata/RHSA-2007-0957.html
- http://mail.gnome.org/archives/ekiga-list/2007-September/msg00103.html
- http://www.ubuntu.com/usn/usn-562-1
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11398
- http://www.s21sec.com/avisos/s21sec-037-en.txt
- http://www.securityfocus.com/archive/1/482120/30/4500/threaded
- http://lists.opensuse.org/opensuse-security-announce/2007-10/msg00006.html
- http://www.vupen.com/english/advisories/2007/3413
- http://www.vupen.com/english/advisories/2007/3414
- https://www.exploit-db.com/exploits/9240
- http://secunia.com/advisories/27524
- http://openh323.cvs.sourceforge.net/openh323/opal/src/sip/sippdu.cxx?r1=2.83.2.19&r2=2.83.2.20
- http://secunia.com/advisories/27128
More from ekiga
View All →Affected Vendor
ekiga
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.