5
CVSSv2

CVE-2004-1940

Published: 31/12/2004 Updated: 15/02/2024
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

sipclient.cpp in KPhone 4.0.1 and previous versions allows remote malicious users to cause a denial of service (crash) via a STUN response packet with a large attrLen value that causes an out-of-bounds read.

Vulnerable Product Search on Vulmon Subscribe to Product

wirlab kphone

Exploits

source: wwwsecurityfocuscom/bid/10159/info A denial of service vulnerability has been reported in KPhone This issue may be triggered by a malformed SIP (Session Initiation Protocol) STUN message This is due to insufficient validation of user-specified STUN packet attribute lengths, causing an out of bounds read and subsequent crash It ...