CVE-2004-1940
5
CVSS Score
Medium
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P
Link copied!
Description
sipclient.cpp in KPhone 4.0.1 and earlier allows remote attackers to cause a denial of service (crash) via a STUN response packet with a large attrLen value that causes an out-of-bounds read.
CVSS Vector Details
Attack Vector
Network
Attack Complexity
Low
Confidentiality
None
Integrity
None
Availability
P
Affected Software Configurations
- a wirlab kphone * * * * * * * *
Weaknesses (CWE)
- CWE-125
References & External Links
- http://marc.info/?l=bugtraq&m=108244325924859&w=2
- http://www.securiteam.com/unixfocus/5PP0B1FCLY.html
- http://www.securityfocus.com/bid/10159
- http://www.wirlab.net/kphone/changes-4.0.2.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15874
- http://marc.info/?l=bugtraq&m=108244325924859&w=2
- http://www.securiteam.com/unixfocus/5PP0B1FCLY.html
- http://www.securityfocus.com/bid/10159
- http://www.wirlab.net/kphone/changes-4.0.2.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15874
External Resources
CVE History Timeline
May 26, 2005 18:51
Initial Analysis
Oct 18, 2016 03:03
CVE Modified
Jul 11, 2017 01:31
CVE Modified
Feb 15, 2024 20:54
Modified Analysis
May 14, 2024 01:27
CVE Modified
Nov 20, 2024 23:52
CVE Modified