REDHAT-BUG-292831: Low severity ekiga vulnerability
Common Vulnerabilities and Exposures assigned an identifier CVE-2007-4897 to the following vulnerability:
The SIPURL::GetHostAddress function in Ekiga (formerly GnomeMeeting) 2.0.5 and earlier allows remote attackers to cause a denial of service (application crash) via unspecified vectors, related to "bad management of memory allocation."
References: http://www.securityfocus.com/bid/25642 http://www.s21sec.com/avisos/s21sec-036-en.txt http://marc.info/?l=full-disclosure&m=118959114522339&w=2
Note: Advisory posted to full-disclosure stated versions 2.0.5 and prior are vulnerable. s21sec site seems to have updated advisory stating version 2.0.7 is also vulnerable.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-292831?
The vulnerability REDHAT-BUG-292831 is considered to be of medium severity due to its potential for causing denial of service.
How do I fix REDHAT-BUG-292831?
To fix REDHAT-BUG-292831, update Ekiga to version 2.0.8 or later, which addresses the vulnerability.
Which versions of Ekiga are affected by REDHAT-BUG-292831?
Ekiga versions 2.0.5 and earlier are affected by the vulnerability REDHAT-BUG-292831.
What type of vulnerability is REDHAT-BUG-292831?
REDHAT-BUG-292831 is categorized as a denial of service vulnerability.
Who can exploit the REDHAT-BUG-292831 vulnerability?
Remote attackers can exploit the REDHAT-BUG-292831 vulnerability to disrupt service availability.