Avaya IP Softphone Remote Denial Of Service Vulnerability
BID:31635
Info
Avaya IP Softphone Remote Denial Of Service Vulnerability
| Bugtraq ID: | 31635 |
| Class: | Design Error |
| CVE: |
CVE-2008-6141 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 08 2008 12:00AM |
| Updated: | May 07 2015 05:22PM |
| Credit: | VoIPshield |
| Vulnerable: |
Avaya IP Softphone 6.1.85 Avaya IP Softphone 6.0 SP4 |
| Not Vulnerable: | |
Discussion
Avaya IP Softphone Remote Denial Of Service Vulnerability
Avaya IP Softphone is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to crash the affected device, denying service to legitimate users.
Given the nature of this issue, the attacker may also be able to run arbitrary code, but this has not been confirmed.
Avaya IP Softphone 6.0 SP4 is vulnerable; other versions may also be affected.
Avaya IP Softphone is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to crash the affected device, denying service to legitimate users.
Given the nature of this issue, the attacker may also be able to run arbitrary code, but this has not been confirmed.
Avaya IP Softphone 6.0 SP4 is vulnerable; other versions may also be affected.
Exploit / POC
Avaya IP Softphone Remote Denial Of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Avaya IP Softphone Remote Denial Of Service Vulnerability
Solution:
The vendor has released an advisory describing possible mitigation factors. Updates are not available yet.
Solution:
The vendor has released an advisory describing possible mitigation factors. Updates are not available yet.
References
Avaya IP Softphone Remote Denial Of Service Vulnerability
References:
References:
- Avaya Homepage (Avaya Inc.)
- Avaya IP Softphone H.323 Denial of Service (VoIPshield)
- ASA-2008-363 - Avaya IP Softphone Denial of Service Vulnerability (Avaya)