Vulnerabilities > Openh323 Project > Openh323

DATE CVE VULNERABILITY TITLE RISK
2007-10-08 CVE-2007-4924 Improper Input Validation vulnerability in multiple products
The Open Phone Abstraction Library (opal), as used by (1) Ekiga before 2.0.10 and (2) OpenH323 before 2.2.4, allows remote attackers to cause a denial of service (crash) via an invalid Content-Length header field in Session Initiation Protocol (SIP) packets, which causes a \0 byte to be written to an "attacker-controlled address."
network
low complexity
ekiga openh323-project CWE-20
5.0