First published: Wed Apr 25 2007(Updated: )
The Linksys SPA941 VoIP Phone allows remote attackers to cause a denial of service (device reboot) via a 0377 (0xff) character in the From header, and possibly certain other locations, in a SIP INVITE request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linksys SPA941 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2270 is considered to have a medium severity due to its ability to cause denial of service by rebooting the device.
To fix CVE-2007-2270, update the firmware of the Linksys SPA941 to a version that addresses this vulnerability.
CVE-2007-2270 involves a denial of service attack that is triggered by sending a specially crafted SIP INVITE request.
CVE-2007-2270 specifically affects the Linksys SPA941 VoIP Phone, making it susceptible to remote attacks.
Attackers can cause the Linksys SPA941 VoIP Phone to reboot, resulting in disruption of service.