![]() |
Buffer overflow vulnerability in Avaya one-X Desktop Edition may allow an attacker to cause denial of service
OverviewA buffer overflow vulnerability SIP message parsing module of Avaya one-X Desktop Edition SIP phone may allow a remote attacker to partially disable the phone. ImpactSuccessfully sending a malformed message to the phone disables the phone from receiving new calls, causing denial of service to the user. The phone may also repeatedly call last dialed number few times. Description
Avaya one-X™ Desktop Edition, formerly Avaya SIP soft phone, transforms Windows-based PCs into SIP-based collaboration endpoints. A buffer overflow vulnerability exists in the SIP header parsing module of Avaya one-X phone which may allow a remote attacker to disable the phone’s call receiving capability. If an attacker can send a malformed SIP message to the phone, the phone may not be able to receive further new calls causing denial of service to the user. User may not know this unless explicitly informed by other users. The phone must be restarted to recover from this state. Solution
Phone SIP stack implementation should be patched to prevent exploiting such vulnerability. Vendor Response:Avaya: The official response for the one-X Desktop Edition vulnerabilities, ASA-2007-241, is posted at http://support.avaya.com/elmodocs2/security/ASA-2007-241.htmFor more information on any of these threat advisories, please email Sipera VIPER Lab at viper@sipera.com |
UC Security Defined
Sipera Systems, the leader in real-time Unified
Communications (UC) security, is the choice of enterprises
and service providers around the world to support their
mission-critical UC deployments.
Sipera offers groundbreaking, production-proven solutions
that secure voice, video, messaging, collaboration, and
other real-time communications in converged IP networks,
boosting compliance with information security requirements.
Backed by the industry-leading research of the VIPER lab,
Sipera's solutions provide comprehensive threat protection,
policy enforcement, access control, and encryption in a
single flexible appliance.