Interaction SIP Proxy Remote Heap Corruption Denial Of Service Vulnerability
BID:16001
Info
Interaction SIP Proxy Remote Heap Corruption Denial Of Service Vulnerability
| Bugtraq ID: | 16001 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 21 2005 12:00AM |
| Updated: | Dec 21 2005 12:00AM |
| Credit: | Behrang Fouladi <[email protected]> is credited with the discovery of this issue. |
| Vulnerable: |
Interactive Intelligence Interaction SIP Proxy 3.0 .010 |
| Not Vulnerable: | |
Discussion
Interaction SIP Proxy Remote Heap Corruption Denial Of Service Vulnerability
Interaction SIP Proxy is susceptible to a remote denial of service vulnerability. This issue is due to a failure of the application to properly bounds check user-supplied input data, resulting in a heap memory corruption.
This issue allows remote attackers to crash the affected server application, denying further telephony service to legitimate users. It may be possible to exploit this issue for remote code execution, but this has not been confirmed.
Version 3.0.010 of Interaction SIP Proxy is vulnerable to this issue; other versions may also be affected.
Interaction SIP Proxy is susceptible to a remote denial of service vulnerability. This issue is due to a failure of the application to properly bounds check user-supplied input data, resulting in a heap memory corruption.
This issue allows remote attackers to crash the affected server application, denying further telephony service to legitimate users. It may be possible to exploit this issue for remote code execution, but this has not been confirmed.
Version 3.0.010 of Interaction SIP Proxy is vulnerable to this issue; other versions may also be affected.
Exploit / POC
Interaction SIP Proxy Remote Heap Corruption Denial Of Service Vulnerability
A proof of concept denial of service exploit is available:
A proof of concept denial of service exploit is available:
Solution / Fix
Interaction SIP Proxy Remote Heap Corruption Denial Of Service Vulnerability
Solution:
The reporter of this issue states that the vendor has provided fixes to address this issue, but this has not been confirmed by Symantec. Users of affected packages should contact the vendor for further information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
The reporter of this issue states that the vendor has provided fixes to address this issue, but this has not been confirmed by Symantec. Users of affected packages should contact the vendor for further information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Interaction SIP Proxy Remote Heap Corruption Denial Of Service Vulnerability
References:
References:
- Interaction SIP Proxy Product Page (Interactive Intelligence)
- [Hat-Squad] Remote Heap Corruption Vulnerability in Interaction SIP Proxy ([email protected])