CVE-2007-4897: Medium severity Ekiga Ekiga vulnerability

Published Sep 12, 2007
·
Updated

Common Vulnerabilities and Exposures assigned an identifier CVE-2007-4897 to the following vulnerability:

The SIPURL::GetHostAddress function in Ekiga (formerly GnomeMeeting) 2.0.5 and earlier allows remote attackers to cause a denial of service (application crash) via unspecified vectors, related to "bad management of memory allocation."

References: http://www.securityfocus.com/bid/25642 http://www.s21sec.com/avisos/s21sec-036-en.txt http://marc.info/?l=full-disclosure&m=118959114522339&w=2

Note: Advisory posted to full-disclosure stated versions 2.0.5 and prior are vulnerable. s21sec site seems to have updated advisory stating version 2.0.7 is also vulnerable.

Other sources

pwlib, as used by Ekiga 2.0.5 and possibly other products, allows remote attackers to cause a denial of service (application crash) via a long argument to the PString::vsprintf function, related to a "memory management flaw". NOTE: this issue was originally reported as being in the SIPURL::GetHostAddress function in Ekiga (formerly GnomeMeeting).

Red Hat

Affected Software

2 affected componentsFixes available
redhat/pwlib<0:1.10.1-7.0.1.el5
0:1.10.1-7.0.1.el5
Ekiga Ekiga=2.0.5

Event History

Sep 12, 2007
CVE Published
via Red Hat·12:00 AM
Sep 14, 2007
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Sep 17, 2007
Data Sourced
via Red Hat·08:11 AM
DescriptionSeverityAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2007-4897?

CVE-2007-4897 is classified as a denial of service vulnerability that can cause an application crash.

2

How do I fix CVE-2007-4897?

To fix CVE-2007-4897, upgrade to pwlib version 1.10.1-7.0.1.el5 or later.

3

Which applications are affected by CVE-2007-4897?

CVE-2007-4897 specifically affects Ekiga version 2.0.5 and possibly other software using pwlib.

4

What type of vulnerability is CVE-2007-4897?

CVE-2007-4897 is a memory management flaw that allows remote attackers to exploit the PString::vsprintf function.

5

Can CVE-2007-4897 be exploited remotely?

Yes, CVE-2007-4897 can be exploited remotely by attackers through crafted input to the vulnerable application.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203