VDB
CVE-2007-4924
CVE-2007-4924
PUBLISHED
CVSS 5 MEDIUM
The Open Phone Abstraction Library (opal), as used by (1) Ekiga before 2.0.10 and (2) OpenH323 before 2.2.4, allows remote attackers to cause a denial of service (crash) via an invalid Content-Length header field in Session Initiation Protocol (SIP) packets, which causes a \0 byte to be written to an "attacker-controlled address."
EPSS 23.13% · 96.0th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
23.13%
96.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| openh323_project | openh323 | 0 |
| ekiga | ekiga | 0 |
Timeline
- Oct 8, 2007 CVE Published
- Jul 23, 2009 PoC Published
- Jul 24, 2009 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 1, 2022 CVE Updated
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
References
- 27118 third-party-advisory
- 27271 third-party-advisory
- 1018776 vdb
- 25955 vdb
- 27129 third-party-advisory
- MDKSA-2007:205 vendor-advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=296371 url
- 28380 third-party-advisory
- 41637 vdb
- RHSA-2007:0957 vendor-advisory
- [ekiga-list] 20070917 [ANNOUNCE] Ekiga 2.0.10 released mailing-list
- USN-562-1 vendor-advisory
- oval:org.mitre.oval:def:11398 vdb
- http://www.s21sec.com/avisos/s21sec-037-en.txt url
- 20071011 S21SEC-037-en: OPAL SIP Protocol Remote Denial of Service mailing-list
- SUSE-SR:2007:021 vendor-advisory
- ADV-2007-3413 vdb
- ADV-2007-3414 vdb
- 9240 exploit
- 27524 third-party-advisory
…and 3 more