First published: Tue Oct 23 2007(Updated: )
Buffer overflow in the Nortel UNIStim IP Softphone 2050 allows remote attackers to cause a denial of service (application abort) and possibly execute arbitrary code via a flood of invalid characters to the RTCP port (5678/udp) that triggers a Windows error message, aka "extraneous messaging."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nortel IP Softphone 2050 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5636 has a high severity rating due to its potential to cause a denial of service and execute arbitrary code.
To address CVE-2007-5636, users should update to the latest version of the Nortel IP Softphone 2050 or apply any available patches.
CVE-2007-5636 is classified as a buffer overflow vulnerability.
CVE-2007-5636 can be exploited by remote attackers sending a flood of invalid characters to the RTCP port 5678/udp.
The impacts of CVE-2007-5636 include application crashes and the possibility of remote code execution.