First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 188748
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Matt Fleming <mjf@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 188748 depends on: Show dependency tree
Show dependency graph
Bug 188748 blocks:

Additional Comments: (this is where you put emerge --info)







View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2007-08-13 21:06 0000
A message validation check flaw in WengoPhone SIP phone implementation may
allow a remote attacker to crash the phone causing denial of service.

The vulnerability occurs as a result of how the SIP client component handles an
incorrectly formatted sip packet. MESSAGE is a sip method for Instant
Messaging. After WengoPhone receive a malformed packet without "Content-Type"
field, we call "Missing Content-Type Vulnerability", it will be crash.

------- Comment #1 From Matt Fleming 2007-08-13 21:08:39 0000 -------
CC'ing herd and setting whiteboard status.

------- Comment #2 From Chi-Thanh Christopher Nguyen 2007-08-27 14:33:34 0000 -------
This is CVE-2007-4366
wengophone-2.1.2 has been released which fixes the issue.
http://blog.openwengo.org/index.php?/archives/96-WengoPhone-releases-2.1.2-and-2.2-alpha-1.html

------- Comment #3 From Olivier Crete 2007-09-05 21:36:26 0000 -------
I've put the new version of wengophone in the tree, and removed all old
versions.
I also removed the downloads of pre-built libraries from debian for amd64. WTF
was that? We have emul lib packages for such cases, in any case I think they
are included in the package now, so external libs are not needed. I will try to
test on amd64 tonight or tomorrow to make sure I haven't broken anything.

------- Comment #4 From Christian Faulhammer 2007-09-08 21:57:32 0000 -------
No stabilisation needed here, so removing amd64, there were no complaints up to
now.  Olivier, I add you to cc instead alone.  As it is a minor issue (4), I
set whiteboard to [noglsa] and ask security team to close this bug.

------- Comment #5 From Pierre-Yves Rofes 2007-09-08 22:03:20 0000 -------
(In reply to comment #4)
> No stabilisation needed here, so removing amd64, there were no complaints up to
> now.  Olivier, I add you to cc instead alone.  As it is a minor issue (4), I
> set whiteboard to [noglsa] and ask security team to close this bug.
> 

right, closing without glsa. Thanks again for your help opfer.

First Last Prev Next    No search results available      Search page      Enter new bug