CVE-2007-4924: Input Validation
José Miguel Esparza discovered that insufficient input validation is performed on SIP protocol header field 'Content-Length' by opal library used by ekiga. This flaw can be used to write '\0' byte to attacker-controlled address and crash ekiga. Ekiga 2.0.10 using opal library 2.2.10 was released to address this issue.
Ekiga 2.0.10 release notes: http://mail.gnome.org/archives/ekiga-list/2007-September/msg00103.html
CVS commit pointed out by upstream: http://openh323.cvs.sourceforge.net/openh323/opal/src/sip/sippdu.cxx?r1=2.83.2.19&r2=2.83.2.20&pathrev=Phobos (some of the previous commits may be required to get complete checks / fix)
Other sources
The Open Phone Abstraction Library (opal), as used by (1) Ekiga before 2.0.10 and (2) OpenH323 before 2.2.4, allows remote attackers to cause a denial of service (crash) via an invalid Content-Length header field in Session Initiation Protocol (SIP) packets, which causes a \0 byte to be written to an "attacker-controlled address."
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4924?
CVE-2007-4924 is classified as a denial of service vulnerability.
How do I fix CVE-2007-4924?
To fix CVE-2007-4924, update Ekiga to version 2.0.10 or later and OpenH323 to version 2.2.4 or later.
What software is affected by CVE-2007-4924?
CVE-2007-4924 affects Ekiga versions up to 2.0.9 and OpenH323 versions up to 2.2.3.
What type of attack can exploit CVE-2007-4924?
CVE-2007-4924 can be exploited through malicious SIP packets containing an invalid Content-Length header.
When was CVE-2007-4924 reported?
CVE-2007-4924 was reported in September 2007.