AGEphone SIP Packet Handling Buffer Overflow Vulnerability
BID:19148
CVE-2006-4029 |Info
AGEphone SIP Packet Handling Buffer Overflow Vulnerability
| Bugtraq ID: | 19148 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 25 2006 12:00AM |
| Updated: | Jul 25 2006 10:17PM |
| Credit: | Discovered by Tan Chew Keong. |
| Vulnerable: |
Ageet AGEphone 1.38.1 Ageet AGEphone 1.28 |
| Not Vulnerable: |
Ageet AGEphone 1.40 |
Discussion
AGEphone SIP Packet Handling Buffer Overflow Vulnerability
AGEphone is prone to a remote buffer-overflow vulnerability.
Specifically, this issue presents itself when the application handles a malicious SIP (Session Initiation Protocol) packet.
AGEphone versions 1.24 and 1.38.1 are reported vulnerable; other versions may be affected as well.
AGEphone is prone to a remote buffer-overflow vulnerability.
Specifically, this issue presents itself when the application handles a malicious SIP (Session Initiation Protocol) packet.
AGEphone versions 1.24 and 1.38.1 are reported vulnerable; other versions may be affected as well.
Exploit / POC
AGEphone SIP Packet Handling Buffer Overflow Vulnerability
The researcher responsible for discovering this issue has developed an exploit, but it is currently not publicly available.
The following proof of concept is available:
The researcher responsible for discovering this issue has developed an exploit, but it is currently not publicly available.
The following proof of concept is available:
Solution / Fix
AGEphone SIP Packet Handling Buffer Overflow Vulnerability
Solution:
The vendor has released version 1.40 to address this issue.
Ageet AGEphone 1.28
Ageet AGEphone 1.38.1
Solution:
The vendor has released version 1.40 to address this issue.
Ageet AGEphone 1.28
-
Ageet AGEphone 1.40
http://www.ageet.com/us/download.htm
Ageet AGEphone 1.38.1
-
Ageet AGEphone 1.40
http://www.ageet.com/us/download.htm
References
AGEphone SIP Packet Handling Buffer Overflow Vulnerability
References:
References: