7.8

CVE-2007-1693

Exploit
The SIP channel module in Yet Another Telephony Engine (Yate) before 1.2.0 sets the caller_info_uri parameter using an incorrect variable that can be NULL, which allows remote attackers to cause a denial of service (NULL dereference and application crash) via a Call-Info header without a purpose parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
YateYet Another Telephony Engine Version <= 1.1.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.35% 0.815
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://securityreason.com/securityalert/2716
Third Party Advisory
Exploit
http://voip.null.ro/cgi-bin/cvsweb.cgi/yate/modules/ysipchan.cpp
Third Party Advisory
Issue Tracking
http://www.securityfocus.com/archive/1/467289/100/200/threaded
Third Party Advisory
VDB Entry
http://www.securityfocus.com/bid/23746
Third Party Advisory
VDB Entry