First published: Wed Sep 12 2007(Updated: )
pwlib, as used by Ekiga 2.0.5 and possibly other products, allows remote attackers to cause a denial of service (application crash) via a long argument to the PString::vsprintf function, related to a "memory management flaw". NOTE: this issue was originally reported as being in the SIPURL::GetHostAddress function in Ekiga (formerly GnomeMeeting).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/pwlib | <0:1.10.1-7.0.1.el5 | 0:1.10.1-7.0.1.el5 |
Ekiga | =2.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4897 is classified as a denial of service vulnerability that can cause an application crash.
To fix CVE-2007-4897, upgrade to pwlib version 1.10.1-7.0.1.el5 or later.
CVE-2007-4897 specifically affects Ekiga version 2.0.5 and possibly other software using pwlib.
CVE-2007-4897 is a memory management flaw that allows remote attackers to exploit the PString::vsprintf function.
Yes, CVE-2007-4897 can be exploited remotely by attackers through crafted input to the vulnerable application.