Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 188748 - net-voip/wengophone-bin 2.x DoS vulnerability (CVE-2007-4366)
Summary: net-voip/wengophone-bin 2.x DoS vulnerability (CVE-2007-4366)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://www.securityfocus.com/archive/...
Whiteboard: ~4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2007-08-13 21:06 UTC by Matt Fleming (RETIRED)
Modified: 2007-09-08 22:03 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Matt Fleming (RETIRED) gentoo-dev 2007-08-13 21:06:55 UTC
A message validation check flaw in WengoPhone SIP phone implementation may allow a remote attacker to crash the phone causing denial of service.

The vulnerability occurs as a result of how the SIP client component handles an incorrectly formatted sip packet. MESSAGE is a sip method for Instant Messaging. After WengoPhone receive a malformed packet without "Content-Type" field, we call "Missing Content-Type Vulnerability", it will be crash.
Comment 1 Matt Fleming (RETIRED) gentoo-dev 2007-08-13 21:08:39 UTC
CC'ing herd and setting whiteboard status.
Comment 2 Chí-Thanh Christopher Nguyễn gentoo-dev 2007-08-27 14:33:34 UTC
This is CVE-2007-4366
wengophone-2.1.2 has been released which fixes the issue.
http://blog.openwengo.org/index.php?/archives/96-WengoPhone-releases-2.1.2-and-2.2-alpha-1.html
Comment 3 Olivier Crete (RETIRED) gentoo-dev 2007-09-05 21:36:26 UTC
I've put the new version of wengophone in the tree, and removed all old versions.
I also removed the downloads of pre-built libraries from debian for amd64. WTF was that? We have emul lib packages for such cases, in any case I think they are included in the package now, so external libs are not needed. I will try to test on amd64 tonight or tomorrow to make sure I haven't broken anything.
Comment 4 Christian Faulhammer (RETIRED) gentoo-dev 2007-09-08 21:57:32 UTC
No stabilisation needed here, so removing amd64, there were no complaints up to now.  Olivier, I add you to cc instead alone.  As it is a minor issue (4), I set whiteboard to [noglsa] and ask security team to close this bug.
Comment 5 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-09-08 22:03:20 UTC
(In reply to comment #4)
> No stabilisation needed here, so removing amd64, there were no complaints up to
> now.  Olivier, I add you to cc instead alone.  As it is a minor issue (4), I
> set whiteboard to [noglsa] and ask security team to close this bug.
> 

right, closing without glsa. Thanks again for your help opfer.