SX Design sipd Remote Denial of Service Vulnerability
BID:9198
Info
SX Design sipd Remote Denial of Service Vulnerability
| Bugtraq ID: | 9198 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 11 2003 12:00AM |
| Updated: | Dec 11 2003 12:00AM |
| Credit: | The disclosure of this issue has been credited to STORM. |
| Vulnerable: |
SX Design sipd 0.1.2 |
| Not Vulnerable: |
SX Design sipd 0.1.4 |
Discussion
SX Design sipd Remote Denial of Service Vulnerability
It has been reported that sipd may be prone to a vulnerability that may allow a remote attacker to cause a denial of service condition in the software. The problem is reported to exist in the gethostbyname_r function. An attacker may be able to cause the server to crash by sending a malformed SIP request.
sipd version 0.1.2 has been reported to be prone to this issue, however other versions could be affected as well.
It has been reported that sipd may be prone to a vulnerability that may allow a remote attacker to cause a denial of service condition in the software. The problem is reported to exist in the gethostbyname_r function. An attacker may be able to cause the server to crash by sending a malformed SIP request.
sipd version 0.1.2 has been reported to be prone to this issue, however other versions could be affected as well.
Exploit / POC
SX Design sipd Remote Denial of Service Vulnerability
The following proof of concept exploit has been provided:
The following proof of concept exploit has been provided:
Solution / Fix
SX Design sipd Remote Denial of Service Vulnerability
Solution:
It has been reported that sipd version 0.1.4 is not vulnerable to this issue. Users are advised to download the fixed version of the software.
SX Design sipd 0.1.2
Solution:
It has been reported that sipd version 0.1.4 is not vulnerable to this issue. Users are advised to download the fixed version of the software.
SX Design sipd 0.1.2
-
SX Design sipd-0.1.4.tar.bz2
http://www.sxdesign.com/download/sipd-0.1.4.tar.bz2
References
SX Design sipd Remote Denial of Service Vulnerability
References:
References:
- sipD gethostbyname_r DoS (SecuriTeam)
- sipd homepage (SX Design)