CVE Database
/

CVE-2006-0738

Back to search

CVE-2006-0738

Published: Feb 17, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple format string vulnerabilities in eStara SIP softphone allow remote attackers to cause a denial of service (hang) via SIP INVITE requests with format string specifiers in the SDP session description, as demonstrated using (1) the field name, (2) the o field (owner/creator and session identifier), or (3) the m field (media name and transport address).

VendorProductVersions

n/a

n/a

affected
n/a

References

18872
third-party-advisory
x_refsource_SECUNIA
ADV-2006-0607
vdb-entry
x_refsource_VUPEN
estara-sdp-format-string(24678)
vdb-entry
x_refsource_XF
16629
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now