漏洞信息详情
KPhone Malformed STUN Packet拒绝服务漏洞
- CNNVD编号:CNNVD-200412-270
- 危害等级: 中危
- CVE编号:
CVE-2004-1940
- 漏洞类型:
其他
- 发布时间:
2004-12-31
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
kphone - 漏洞来源:
Discovery is credi… -
漏洞简介
KPhone 4.0.1及其以前版本的sipclient.cpp存在漏洞。远程攻击者借助STUN响应包导致服务拒绝(崩溃),这个STUN响应包具有超大attrLen值导致out-of-bounds读取。
漏洞公告
This issue has been addressed in KPhone 4.0.2.
KPhone KPhone 2.0
-
KPhone kphone-4.0.2.tar.gz
http://www.wirlab.net/kphone/kphone-4.0.2.tar.gz
KPhone KPhone 2.1
-
KPhone kphone-4.0.2.tar.gz
http://www.wirlab.net/kphone/kphone-4.0.2.tar.gz
KPhone KPhone 2.11
-
KPhone kphone-4.0.2.tar.gz
http://www.wirlab.net/kphone/kphone-4.0.2.tar.gz
KPhone KPhone 3.0
-
KPhone kphone-4.0.2.tar.gz
http://www.wirlab.net/kphone/kphone-4.0.2.tar.gz
KPhone KPhone 3.1
-
KPhone kphone-4.0.2.tar.gz
http://www.wirlab.net/kphone/kphone-4.0.2.tar.gz
KPhone KPhone 3.11
-
KPhone kphone-4.0.2.tar.gz
http://www.wirlab.net/kphone/kphone-4.0.2.tar.gz
KPhone KPhone 3.12
-
KPhone kphone-4.0.2.tar.gz
http://www.wirlab.net/kphone/kphone-4.0.2.tar.gz
KPhone KPhone 3.13
-
KPhone kphone-4.0.2.tar.gz
http://www.wirlab.net/kphone/kphone-4.0.2.tar.gz
KPhone KPhone 3.14
-
KPhone kphone-4.0.2.tar.gz
http://www.wirlab.net/kphone/kphone-4.0.2.tar.gz
KPhone KPhone 4.0.1
-
KPhone kphone-4.0.2.tar.gz
http://www.wirlab.net/kphone/kphone-4.0.2.tar.gz
参考网址
来源: www.wirlab.net
链接:http://www.wirlab.net/kphone/changes-4.0.2.html
来源: BID
名称: 10159
链接:http://www.securityfocus.com/bid/10159
来源: XF
名称: kphone-stun-dos(15874)
链接:http://xforce.iss.net/xforce/xfdb/15874
来源: www.securiteam.com
链接:http://www.securiteam.com/unixfocus/5PP0B1FCLY.html
来源: BUGTRAQ
名称: 20040419 KPhone STUN DoS (Malformed STUN Packets)
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=108244325924859&w=2