Ekiga GetHostAddress Remote Denial of Service Vulnerability
BID:25642
Info
Ekiga GetHostAddress Remote Denial of Service Vulnerability
| Bugtraq ID: | 25642 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2007-4897 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 11 2007 12:00AM |
| Updated: | Jul 27 2009 10:15PM |
| Credit: | Jose Miguel Esparza reported that this issue was discovered with the Malybuzz fuzzer. |
| Vulnerable: |
Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Redhat Enterprise Linux Optional Productivity Application 5 server Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux Desktop 5 client pwlib pwlib 1.10.10 pwlib pwlib 1.10.5 pwlib pwlib 1.10.2 pwlib pwlib 1.5.2 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 Mandriva Linux Mandrake 2007.0 x86_64 Mandriva Linux Mandrake 2007.0 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 Ekiga Ekiga 2.0.5 Ekiga Ekiga 2.0.4 Ekiga Ekiga 2.0.3 Ekiga Ekiga 2.0.2 Ekiga Ekiga 2.0.1 |
| Not Vulnerable: | |
Discussion
Ekiga GetHostAddress Remote Denial of Service Vulnerability
Ekiga is prone to a remote denial-of-service vulnerability because of memory mismanagement when handling user-supplied data.
Successfully exploiting this issue allows remote attackers to deny service to legitimate users.
Ekiga 2.0.5 and prior versions are reported vulnerable.
Ekiga is prone to a remote denial-of-service vulnerability because of memory mismanagement when handling user-supplied data.
Successfully exploiting this issue allows remote attackers to deny service to legitimate users.
Ekiga 2.0.5 and prior versions are reported vulnerable.
Exploit / POC
Ekiga GetHostAddress Remote Denial of Service Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
Ekiga GetHostAddress Remote Denial of Service Vulnerability
Solution:
Reports indicate that Ekiga 2.0.7 and subsequent versions may not be affected by this vulnerability. Symantec could not confirm this information.
Please see the referenced advisories for more information.
Solution:
Reports indicate that Ekiga 2.0.7 and subsequent versions may not be affected by this vulnerability. Symantec could not confirm this information.
Please see the referenced advisories for more information.
References
Ekiga GetHostAddress Remote Denial of Service Vulnerability
References:
References: