>> SIPfoundry sipXtapi "CSeq" Field Handling Remote Buffer Overflow Vulnerability
Title : SIPfoundry sipXtapi "CSeq" Field Handling Remote Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2006-2735 CVE ID : CVE-2006-3524
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-07-10
Technical Description
A vulnerability has been identified in SIPfoundry sipXtapi, which could be exploited by attackers to execute arbitrary commands. This flaw is due to a buffer overflow error when handling a packet with an overly long "CSeq" field, which could be exploited by attackers to compromise a vulnerable system via a specially crafted packet.