eStara Softphone SIP SDP Data Packet Remote Buffer Overflow Vulnerability
BID:16213
Info
eStara Softphone SIP SDP Data Packet Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 16213 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 11 2006 12:00AM |
| Updated: | Jan 17 2006 10:10PM |
| Credit: | ZwelL <[email protected]> is credited with the discovery of this issue. |
| Vulnerable: |
eStara SoftPhone 3.0.1 .46 eStara SoftPhone 3.0.1 .14 |
| Not Vulnerable: |
eStara SoftPhone 3.0.1 .47 |
Discussion
eStara Softphone SIP SDP Data Packet Remote Buffer Overflow Vulnerability
A remote buffer overflow vulnerability affects eStara Softphone. This issue is due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into static process buffers.
An attacker may exploit this issue to execute arbitrary code with the privileges of the vulnerable application. This may facilitate unauthorized access or privilege escalation.
eStara Softphone versions 3.0.1.14, and 3.0.1.46 are vulnerable to this issue; other versions may also be affected.
A remote buffer overflow vulnerability affects eStara Softphone. This issue is due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into static process buffers.
An attacker may exploit this issue to execute arbitrary code with the privileges of the vulnerable application. This may facilitate unauthorized access or privilege escalation.
eStara Softphone versions 3.0.1.14, and 3.0.1.46 are vulnerable to this issue; other versions may also be affected.
Exploit / POC
eStara Softphone SIP SDP Data Packet Remote Buffer Overflow Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
eStara Softphone SIP SDP Data Packet Remote Buffer Overflow Vulnerability
Solution:
The vendor has released version 3.0.1.47 to address this issue. Users of affected packages can fetch this fixed version by downloading it from the vendor's Web site. For further information on obtaining fixed, contact the vendor.
Solution:
The vendor has released version 3.0.1.47 to address this issue. Users of affected packages can fetch this fixed version by downloading it from the vendor's Web site. For further information on obtaining fixed, contact the vendor.
References
eStara Softphone SIP SDP Data Packet Remote Buffer Overflow Vulnerability
References:
References: