<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
    <channel>
        <title>Sipera Viper Labs: Specific Threats</title>
        <link>http://www.sipera.com/viper</link>
        <pubDate>Fri, 03 Sep 2010 01:46:47 -0500</pubDate>
        <lastBuildDate></lastBuildDate>
        <generator>ContentFeeder 2.0</generator>
        <item>
            <title>Vonage VoIP phone adapter vulnerable to server impersonation</title>
            <link>http://www.sipera.com/index.php?action=resources,threat_advisory&tid=357</link>
            <description><![CDATA[The Vonage service used for phone conversations is vulnerable to an attacker sending SIP INVITE messages directly to Vonage customers.]]></description>
        </item>
        <item>
            <title>Vonage SIP servers vulnerable to registration replay attack</title>
            <link>http://www.sipera.com/index.php?action=resources,threat_advisory&tid=358</link>
            <description><![CDATA[A weak authentication vulnerability in Vonage’s SIP server may allow an attacker to send spoofed REGISTER messages to the server. This is possible because authentication credentials sent to the server can be sniffed, copied, and replayed.]]></description>
        </item>
        <item>
            <title>Vonage voice conversation may be vulnerable to eavesdropping</title>
            <link>http://www.sipera.com/index.php?action=resources,threat_advisory&tid=359</link>
            <description><![CDATA[Unencrypted RTP packets in IP-based communication can be captured to reconstruct the media (e.g., voice or video) compromising confidentiality of communication. Vonage phone service does not encrypt voice conversation packets leaving it vulnerable to eavesdropping.]]></description>
        </item>
        <item>
            <title>Vonage VoIP phone adapter vulnerable to flood Denial of Service attack</title>
            <link>http://www.sipera.com/index.php?action=resources,threat_advisory&tid=360</link>
            <description><![CDATA[Vonage phone adapter used for phone conversations over Internet is vulnerable to SIP INVITE message flood attack causing denial of service to users.]]></description>
        </item>
        <item>
            <title>Grandstream HandyTone-488 PSTN-to-VoIP adapter is vulnerable to buffer overflow</title>
            <link>http://www.sipera.com/index.php?action=resources,threat_advisory&tid=361</link>
            <description><![CDATA[Grandstream HT-488 phone adapter can be crashed by sending a specially crafted SIP INVITE message to it’s public IP address.]]></description>
        </item>
        <item>
            <title>Grandstream HandyTone-488 PSTN-to-VoIP adapter is vulnerable to fragmented packet attack</title>
            <link>http://www.sipera.com/index.php?action=resources,threat_advisory&tid=362</link>
            <description><![CDATA[Grandstream HT-488 phone adapter can be crashed by sending a specially a flood of fragmented packets to port 5060.]]></description>
        </item>
        <item>
            <title>Globe7 VoIP service provider online account access is unsecured</title>
            <link>http://www.sipera.com/index.php?action=resources,threat_advisory&tid=363</link>
            <description><![CDATA[Online account access for Globe7 VoIP service provider does not used secured connection. Confidential user information getting transmitted over such unsecured connection is vulnerable to eavesdropping by unauthorized third party.]]></description>
        </item>
        <item>
            <title>Globe7 VoIP Client uses weak encryption to store user credentials</title>
            <link>http://www.sipera.com/index.php?action=resources,threat_advisory&tid=364</link>
            <description><![CDATA[Globe7 soft phone client stores user credentials locally using weak encryption scheme making it vulnerable to reverse engineering attack. ]]></description>
        </item>
        <item>
            <title>Microsoft MSN Messenger vulnerable to resource exhaustion attack and may affect operating system</title>
            <link>http://www.sipera.com/index.php?action=resources,threat_advisory&tid=292</link>
            <description><![CDATA[MSN Messenger used for initiating voice conversation is vulnerable to SIP INVITE message flood attack causing denial of service to users]]></description>
        </item>
        <item>
            <title>AOL Instant Messenger vulnerable to resource exhaustion attack</title>
            <link>http://www.sipera.com/index.php?action=resources,threat_advisory&tid=293</link>
            <description><![CDATA[AOL Instant Messenger used for initiating voice conversation is vulnerable to flood attack causing denial of service to users.]]></description>
        </item>
        <item>
            <title>AOL Instant Messenger crashes when processing a specially crafted SIP message</title>
            <link>http://www.sipera.com/index.php?action=resources,threat_advisory&tid=294</link>
            <description><![CDATA[AOL Instant Messenger used for initiating voice conversation fails to validate SIP messages with a specific malformed content. This vulnerability can be exploited by sending a malformed SIP message directly to the messenger. The messenger must be manually restarted.]]></description>
        </item>
        <item>
            <title>Buffer overflow vulnerability in Avaya one-X Desktop Edition may allow an attacker to cause denial of service</title>
            <link>http://www.sipera.com/index.php?action=resources,threat_advisory&tid=295</link>
            <description><![CDATA[A buffer overflow vulnerability SIP message parsing module of Avaya one-X Desktop Edition SIP phone may allow a remote attacker to partially disable the phone.]]></description>
        </item>
        <item>
            <title>SIP parsing error in Avaya one-X Desktop Edition may allow an attacker to disconnect it from the server and crash</title>
            <link>http://www.sipera.com/index.php?action=resources,threat_advisory&tid=296</link>
            <description><![CDATA[An implementation error in SIP message parsing module of Avaya one-X Desktop Edition SIP phone may allow a remote attacker to crash the phone.]]></description>
        </item>
        <item>
            <title>Buffer overflow vulnerability in Nortel Networks PC Client may allow a remote attacker to execute arbitrary code on the host</title>
            <link>http://www.sipera.com/index.php?action=resources,threat_advisory&tid=297</link>
            <description><![CDATA[A buffer overflow vulnerability SIP message parsing module of Nortel Networks PC Client SIP phone may allow a remote attacker to execute arbitrary code on host machine or crash the phone.]]></description>
        </item>
        <item>
            <title>Improper message parsing vulnerability in Nortel Networks PC Client may allow a remote attacker to crash the client</title>
            <link>http://www.sipera.com/index.php?action=resources,threat_advisory&tid=298</link>
            <description><![CDATA[Nortel Networks PC Client SIP phone may not parse a malformed SIP header value allowing a remote attacker to crash the phone by sending a SIP message with such malformed header to the phone]]></description>
        </item>
    </channel>
</rss>
