Polycom SoundPoint IP 601 SIP Phone CGI Request Remote Denial of Service Vulnerability
BID:24547
Info
Polycom SoundPoint IP 601 SIP Phone CGI Request Remote Denial of Service Vulnerability
| Bugtraq ID: | 24547 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-3368 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 19 2007 12:00AM |
| Updated: | May 07 2015 05:37PM |
| Credit: | Sipera VIPER Lab is credited with the discovery of this vulnerability. |
| Vulnerable: |
Polycom SoundPoint IP 601 0 |
| Not Vulnerable: | |
Discussion
Polycom SoundPoint IP 601 SIP Phone CGI Request Remote Denial of Service Vulnerability
Polycom SoundPoint IP 601 SIP phones are prone to a denial-of-service vulnerability because the devices fail to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
Successfully exploiting this issue allows remote attackers to reboot affected devices, resulting in a denial-of-service condition. Given the nature of the issue, code execution may also be possible, but this has not been confirmed.
Phones with firmware versions in the 3.0 series are vulnerable to this issue; other versions may also be affected.
Polycom SoundPoint IP 601 SIP phones are prone to a denial-of-service vulnerability because the devices fail to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
Successfully exploiting this issue allows remote attackers to reboot affected devices, resulting in a denial-of-service condition. Given the nature of the issue, code execution may also be possible, but this has not been confirmed.
Phones with firmware versions in the 3.0 series are vulnerable to this issue; other versions may also be affected.
Exploit / POC
Polycom SoundPoint IP 601 SIP Phone CGI Request Remote Denial of Service Vulnerability
Attackers likely use a browser to exploit this issue.
Attackers likely use a browser to exploit this issue.
Solution / Fix
Polycom SoundPoint IP 601 SIP Phone CGI Request Remote Denial of Service Vulnerability
Solution:
The vendor acknowledges this issue and states that it will be addressed in a future firmware release. This issue is detailed in the vendor's technical bulletin TB18759. Please contact the vendor for more information.
Solution:
The vendor acknowledges this issue and states that it will be addressed in a future firmware release. This issue is detailed in the vendor's technical bulletin TB18759. Please contact the vendor for more information.
References
Polycom SoundPoint IP 601 SIP Phone CGI Request Remote Denial of Service Vulnerability
References:
References: