CVE-2012-5621: Input Validation
A denial of service flaw was found in the way Ekiga, a Gnome based SIP/H323 teleconferencing application, processed information from certain OPAL connections (UTF-8 strings were not verified for validity prior showing them). A remote attacker (other party with a not UTF-8 valid name) could use this flaw to cause ekiga executable crash.
Upstream bug report: [1] https://bugzilla.gnome.org/showbug.cgi?id=653009
Relevant upstream patch: [2] http://git.gnome.org/browse/ekiga/commit/?id=7d09807257
References: [3] http://ftp.gnome.org/pub/gnome/sources/ekiga/4.0/ekiga-4.0.0.news
Other sources
lib/engine/components/opal/opal-call.cpp in ekiga before 4.0.0 allows remote attackers to cause a denial of service (crash) via an OPAL connection with a party name that contains invalid UTF-8 strings.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5621?
CVE-2012-5621 has a severity rating indicating a denial of service vulnerability that could disrupt service for Ekiga users.
How does CVE-2012-5621 affect Ekiga?
CVE-2012-5621 affects Ekiga by allowing a remote attacker to cause a denial of service through invalid UTF-8 strings.
How do I fix CVE-2012-5621?
To fix CVE-2012-5621, upgrade to a version of Ekiga that is above 3.9.90, as later versions have addressed this vulnerability.
Who is impacted by CVE-2012-5621?
Users of Ekiga versions 3.9.90 and below are impacted by CVE-2012-5621 and should take action to mitigate the risk.
Can CVE-2012-5621 be exploited remotely?
Yes, CVE-2012-5621 can be exploited remotely by any party sending invalid UTF-8 data to Ekiga.