MEDIUM · 5.0

CVE-2007-4924

The Open Phone Abstraction Library (opal), as used by (1) Ekiga before 2.0.10 and (2) OpenH323 before 2.2.4, allows remote attackers to cause a denial of service (crash) via an invalid Content-Length ...

Vulnerability Description

The Open Phone Abstraction Library (opal), as used by (1) Ekiga before 2.0.10 and (2) OpenH323 before 2.2.4, allows remote attackers to cause a denial of service (crash) via an invalid Content-Length header field in Session Initiation Protocol (SIP) packets, which causes a \0 byte to be written to an "attacker-controlled address."

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
EkigaEkiga<= 2.0.9
Openh323 ProjectOpenh323<= 2.2.3

Related Weaknesses (CWE)

References

FAQ

What is CVE-2007-4924?

CVE-2007-4924 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The Open Phone Abstraction Library (opal), as used by (1) Ekiga before 2.0.10 and (2) OpenH323 before 2.2.4, allows remote attackers to cause a denial of service (crash) via an invalid Content-Length ...

How severe is CVE-2007-4924?

CVE-2007-4924 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-4924?

Check the references section above for vendor advisories and patch information. Affected products include: Ekiga Ekiga, Openh323 Project Openh323.