The Open Phone Abstraction Library (opal), as used by (1) Ekiga before 2.0.10 and (2) OpenH323 before 2.2.4, allows remote attackers to cause a denial of service (crash) via an invalid Content-Length header field in Session Initiation Protocol (SIP) packets, which causes a \0 byte to be written to an "attacker-controlled address."
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2007-10-08 14:17
Updated : 2018-10-15 14:38
NVD link : CVE-2007-4924
Mitre link : CVE-2007-4924
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
ekiga
- ekiga
openh323_project
- openh323