>> Nortel SIP Multimedia PC Client Remote Denial of Service Vulnerability
Title : Nortel SIP Multimedia PC Client Remote Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2008-1942 CVE ID : CVE-2008-3157 CWE ID : CWE-19 - CWE-400
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-06-27
Technical Description
A vulnerability has been identified in Nortel SIP Multimedia PC Client, which could be exploited by attackers to cause a denial of service. This issue is caused due to the application not limiting the number of sessions, which could be exploited by attackers to exhaust all available memory resources, creating a denial of service condition.
Note: A second issue caused due to a lack of authentication on received SIP INVITE messages could be exploited to propagate SPIT (Spam over Internet Telephony).