CVE Database
/

CVE-2007-5361

Back to search

CVE-2007-5361

Published: Nov 20, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

The Communication Server in Alcatel-Lucent OmniPCX Enterprise 7.1 and earlier caches an IP address during a TFTP request from an IP Touch phone, and uses this IP address as the destination for all subsequent VoIP packets to this phone, which allows remote attackers to cause a denial of service (loss of audio) or intercept voice communications via a crafted TFTP request containing the phone's MAC address in the filename.

VendorProductVersions

n/a

n/a

affected
n/a

References

3387
third-party-advisory
x_refsource_SREASON
27710
third-party-advisory
x_refsource_SECUNIA
26494
vdb-entry
x_refsource_BID
omnipcx-tftp-dos(38560)
vdb-entry
x_refsource_XF
ADV-2007-3919
vdb-entry
x_refsource_VUPEN
40522
vdb-entry
x_refsource_OSVDB
1018983
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now