Vulnerability Description
ZoIPer 2.22, and possibly other versions before 2.24 Library 5324, allows remote attackers to cause a denial of service (crash) via a SIP INVITE request with an empty Call-Info header.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zoiper | Zoiper | <= 2.22 |
References
- http://packetstormsecurity.org/0910-exploits/zoiper_dos.py.txtExploit
- http://secunia.com/advisories/37015Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/53792
- http://packetstormsecurity.org/0910-exploits/zoiper_dos.py.txtExploit
- http://secunia.com/advisories/37015Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/53792
FAQ
What is CVE-2009-3704?
CVE-2009-3704 is a vulnerability with a CVSS score of 5.0 (MEDIUM). ZoIPer 2.22, and possibly other versions before 2.24 Library 5324, allows remote attackers to cause a denial of service (crash) via a SIP INVITE request with an empty Call-Info header.
How severe is CVE-2009-3704?
CVE-2009-3704 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-3704?
Check the references section above for vendor advisories and patch information. Affected products include: Zoiper Zoiper.