vendor:
OpenH323
by:
Jose Miguel Esparza
7,5
CVSS
HIGH
Remote Denial of Service
119
CWE
Product Name: OpenH323
Affected Version From: OpenH323 2.2.7
Affected Version To: OpenH323 2.2.8
Patch Exists: YES
Related CWE: CVE-2007-4924
CPE: a:openh323:openh323
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2007
OpenH323 Opal SIP Protocol Remote Denial of Service Vulnerability (CVE-2007-4924)
This vulnerability is caused by a buffer overflow in the OpenH323 Opal SIP Protocol. A malformed SIP INVITE request with a negative Content-Length header can cause a denial of service condition. The vulnerable code is located in the sip/sipcon.cxx file.
Mitigation:
The vendor has released a patch to address this vulnerability.