Nortel Networks PC Client Soft Phone SIP Message Parsing Module Denial of Service Vulnerability
BID:24536
Info
Nortel Networks PC Client Soft Phone SIP Message Parsing Module Denial of Service Vulnerability
| Bugtraq ID: | 24536 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2007-3361 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 19 2007 12:00AM |
| Updated: | Oct 17 2007 01:27AM |
| Credit: | Sipera VIPER lab team is credited with discovering this issue. |
| Vulnerable: |
Nortel Networks PC Client SIP Soft Phone 4.1 Nortel Networks Multimedia Comm MCS5100 |
| Not Vulnerable: | |
Discussion
Nortel Networks PC Client Soft Phone SIP Message Parsing Module Denial of Service Vulnerability
Nortel Networks PC Client soft phone is prone to a remote denial-of-service vulnerability because the application fails to properly handle malformed data.
Successful exploits can allow remote attackers to crash the affected application, denying further service to legitimate users.
Nortel Networks PC Client soft phone is prone to a remote denial-of-service vulnerability because the application fails to properly handle malformed data.
Successful exploits can allow remote attackers to crash the affected application, denying further service to legitimate users.
Exploit / POC
Nortel Networks PC Client Soft Phone SIP Message Parsing Module Denial of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution / Fix
Nortel Networks PC Client Soft Phone SIP Message Parsing Module Denial of Service Vulnerability
Solution:
The vendor has released an advisory along with fixes to address this issue. Please see the references for more information.
Solution:
The vendor has released an advisory along with fixes to address this issue. Please see the references for more information.
References
Nortel Networks PC Client Soft Phone SIP Message Parsing Module Denial of Service Vulnerability
References:
References:
- Nortel Networks Homepage (Nortel Networks)
- Nortel Security Advisory 2007008347, Rev 1 Potential Denial of Service Attack Vu (Nortel Networks)
- VIPER-2007-045: Improper message parsing vulnerability in Nortel Networks PC Cli (Sipera)