CVE-2007-4897: Medium severity Ekiga Ekiga vulnerability
Common Vulnerabilities and Exposures assigned an identifier CVE-2007-4897 to the following vulnerability:
The SIPURL::GetHostAddress function in Ekiga (formerly GnomeMeeting) 2.0.5 and earlier allows remote attackers to cause a denial of service (application crash) via unspecified vectors, related to "bad management of memory allocation."
References: http://www.securityfocus.com/bid/25642 http://www.s21sec.com/avisos/s21sec-036-en.txt http://marc.info/?l=full-disclosure&m=118959114522339&w=2
Note: Advisory posted to full-disclosure stated versions 2.0.5 and prior are vulnerable. s21sec site seems to have updated advisory stating version 2.0.7 is also vulnerable.
Other sources
pwlib, as used by Ekiga 2.0.5 and possibly other products, allows remote attackers to cause a denial of service (application crash) via a long argument to the PString::vsprintf function, related to a "memory management flaw". NOTE: this issue was originally reported as being in the SIPURL::GetHostAddress function in Ekiga (formerly GnomeMeeting).
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4897?
CVE-2007-4897 is classified as a denial of service vulnerability that can cause an application crash.
How do I fix CVE-2007-4897?
To fix CVE-2007-4897, upgrade to pwlib version 1.10.1-7.0.1.el5 or later.
Which applications are affected by CVE-2007-4897?
CVE-2007-4897 specifically affects Ekiga version 2.0.5 and possibly other software using pwlib.
What type of vulnerability is CVE-2007-4897?
CVE-2007-4897 is a memory management flaw that allows remote attackers to exploit the PString::vsprintf function.
Can CVE-2007-4897 be exploited remotely?
Yes, CVE-2007-4897 can be exploited remotely by attackers through crafted input to the vulnerable application.