vendor:
Triton VoIP Client
by:
c0rrupt
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Triton VoIP Client
Affected Version From: 1.0.4
Affected Version To: 1.0.4
Patch Exists: YES
Related CWE: N/A
CPE: a:triton:triton_voip_client
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP2
2007
Triton sipxtapi Buffer Overflow
This exploit sends a specially crafted udp packet to the triton client which leads to command execution through a buffer overflow. The Triton client does not open the sipxtapi port 5061 by default. The port is open when the client attemps to try any talk session, and stays open for the remainder of the time it is running.
Mitigation:
Patch the vulnerable version of Triton.