>> Nortel PC Client SIP Soft Phone Headers Processing Denial of Service Vulnerabilities
Title : Nortel PC Client SIP Soft Phone Headers Processing Denial of Service Vulnerabilities VUPEN ID : VUPEN/ADV-2007-2319 CVE ID : CVE-2007-3361 - CVE-2007-3438
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-06-26
Technical Description
Two vulnerabilities have been identified in Nortel PC Client SIP Soft Phone, which could be exploited by remote attackers to cause a denial of service or potentially execute arbitrary code. These issues are caused by errors when processing SIP (Session Initiation Protocol) messages with a specially crafted header, which could be exploited by attackers to crash or potentially compromise an affected application.