See how opal compares to other vendors in security performance
The Opal Estate Pro – Property Management and Submission plugin for WordPress, used by the FullHouse - Real Estate Responsive WordPress Theme, is vulnerable to privilege escalation via in all versions up to, and including, 1.7.5. This is due to a lack of role restriction during registration in the 'onregiseruser' function. This makes it possible for unauthenticated attackers to arbitrarily choose the role, including the Administrator role, assigned when registering.
Open Phone Abstraction Library (opal) is implementation of varioustelephony and video communication protocols for use over packet based networks.In Red Hat Enterprise Linux 5, the Ekiga application uses opal.A flaw was discovered in the way opal handled certain Session Initiation Protocol (SIP) packets. An attacker could use this flaw to crash an application, such as Ekiga, which is linked with opal. (CVE-2007-4924)Users should upgrade to these updated opal packages which contain a backported patch to correct this issue.
José Miguel Esparza discovered that insufficient input validation is performed on SIP protocol header field 'Content-Length' by opal library used by ekiga. This flaw can be used to write '\0' byte to attacker-controlled address and crash ekiga. Ekiga 2.0.10 using opal library 2.2.10 was released to address this issue.
Ekiga 2.0.10 release notes: http://mail.gnome.org/archives/ekiga-list/2007-September/msg00103.html
CVS commit pointed out by upstream: http://openh323.cvs.sourceforge.net/openh323/opal/src/sip/sippdu.cxx?r1=2.83.2.19&r2=2.83.2.20&pathrev=Phobos (some of the previous commits may be required to get complete checks / fix)