CVE-2007-6093: Input Validation
Published Nov 22, 2007
·Updated
The SRTP implementation in Ingate Firewall before 4.6.0 and SIParator before 4.6.0 allows remote attackers to cause a denial of service (kernel crash) via an RTCP index that is "much more than expected."
Affected Software
2 affected components
Ingate Ingate SIParator<=4.5.2
Ingate Ingate Firewall<=4.5.2
Event History
Nov 22, 2007
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-6093?
CVE-2007-6093 is considered to be a denial of service vulnerability that can cause a kernel crash.
2
How do I fix CVE-2007-6093?
To fix CVE-2007-6093, upgrade the Ingate Firewall or SIParator to version 4.6.0 or later.
3
Who is affected by CVE-2007-6093?
CVE-2007-6093 affects users of Ingate Firewall and Ingate SIParator versions up to 4.5.2.
4
What technical issue does CVE-2007-6093 exploit?
CVE-2007-6093 exploits an improper handling of RTCP indices, leading to a denial of service.
5
Can CVE-2007-6093 be exploited remotely?
Yes, CVE-2007-6093 can be exploited remotely by attackers to cause service disruption.