what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

s21sec-036-en.txt

s21sec-036-en.txt
Posted Sep 13, 2007
Authored by Jose Miguel Esparza | Site s21sec.com

Due to poor memory allocation management, Ekiga versions 2.0.5 and below are susceptible to a denial of service condition.

tags | advisory, denial of service
SHA-256 | f96123da6a4fdf8c6cf9e4c413f57a25dee873f75f0e9569dcef9eb45344294d

s21sec-036-en.txt

Change Mirror Download
##############################################################
- S21Sec Advisory -
##############################################################

Title: Ekiga Denial of Service
ID: S21SEC-036-en
Severity: Medium - Remote DoS
History: 14.May.2007 Vulnerability discovered
09.Jul.2007 Vendor contacted

Scope: Application Denial of Service
Platforms: Any
Author: Jose Miguel Esparza (jesparza@s21sec.com)
URL: http://www.s21sec.com/avisos/s21sec-036-en.txt
Release: Public


[ SUMMARY ]

Ekiga (formely known as GnomeMeeting) is an open source VoIP and
video conferencing application for
GNOME. Ekiga uses both the H.323 and SIP protocols. It supports many
audio and video codecs, and is
interoperable with other SIP compliant software and also with
Microsoft NetMeeting.


[ AFFECTED VERSIONS ]

Following versions are affected with this issue:
- Ekiga 2.0.5 and prior.


[ DESCRIPTION ]

Due to a bad management of memory allocation for the input data it's
possible to crash the application
causing a denial of service.


[ WORKAROUND ]

Upgrade to 2.0.7 or 2.0.9 versions is recommended to resolve this
problem. If not possible, some
additional input data check will be necessary in the
SIPURL::GetHostAddress() function.


[ ACKNOWLEDGMENTS ]

This vulnerability have been found and researched by:
- Jose Miguel Esparza <jesparza@s21sec.com> S21Sec


[ ADDITIONAL INFORMATION ]

This vulnerability has been discovered thanks to the network fuzzer
Malybuzz disponible in the url
http://malybuzz.sourceforge.net/.


[ REFERENCES ]

* Ekiga
http://ekiga.org

* S21Sec
http://www.s21sec.com

* S21sec Blog
http://blog.s21sec.com

* Malybuzz
http://www.s21sec.com/malybuzz/malybuzz.html

Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    0 Files
  • 12
    Nov 12th
    0 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close