Vulnerabilities > CVE-2006-0738 - Denial of Service vulnerability in eStara Softphone

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
estara
exploit available

Summary

Multiple format string vulnerabilities in eStara SIP softphone allow remote attackers to cause a denial of service (hang) via SIP INVITE requests with format string specifiers in the SDP session description, as demonstrated using (1) the field name, (2) the o field (owner/creator and session identifier), or (3) the m field (media name and transport address).

Vulnerable Configurations

Part Description Count
Application
Estara
1

Exploit-Db

descriptioneStara SoftPhone 3.0.1 SIP SDP Message Handling Format String DoS. CVE-2006-0738. Dos exploits for multiple platform
idEDB-ID:27210
last seen2016-02-03
modified2006-02-14
published2006-02-14
reporterZwelL
sourcehttps://www.exploit-db.com/download/27210/
titleeStara SoftPhone 3.0.1 - SIP SDP Message Handling Format String DoS