Nortel Networks PC Client Soft Phone Message Parsing Module Buffer Overflow Vulnerability
BID:24531
Info
Nortel Networks PC Client Soft Phone Message Parsing Module Buffer Overflow Vulnerability
| Bugtraq ID: | 24531 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 19 2007 12:00AM |
| Updated: | Oct 17 2007 01:27AM |
| Credit: | Sipera VIPER lab team is credited with discovering this issue. |
| Vulnerable: |
Nortel Networks PC Client SIP Soft Phone 4.1 Nortel Networks Multimedia Comm MCS5100 |
| Not Vulnerable: | |
Discussion
Nortel Networks PC Client Soft Phone Message Parsing Module Buffer Overflow Vulnerability
Nortel Networks PC Client soft phone is prone to a buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.
Successful exploits can allow remote attackers to execute arbitrary machine code in the context of the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
Nortel Networks PC Client soft phone is prone to a buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.
Successful exploits can allow remote attackers to execute arbitrary machine code in the context of the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
Exploit / POC
Nortel Networks PC Client Soft Phone Message Parsing Module Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution / Fix
Nortel Networks PC Client Soft Phone Message Parsing Module Buffer Overflow Vulnerability
Solution:
The vendor has released updates to address this issue. Please the references for more information.
Solution:
The vendor has released updates to address this issue. Please the references for more information.
References
Nortel Networks PC Client Soft Phone Message Parsing Module Buffer Overflow Vulnerability
References:
References:
- VIPER-2007-044: Buffer overflow vulnerability in Nortel Networks PC Client may a (Sipera)
- Nortel Networks Homepage (Nortel Networks)
- Nortel Security Advisory 2007008347, Rev 1 Potential Denial of Service Attack Vu (Nortel Networks)