The SIP channel module in Yet Another Telephony Engine (Yate) before 1.2.0 sets the caller_info_uri parameter using an incorrect variable that can be NULL, which allows remote attackers to cause a denial of service (NULL dereference and application crash) via a Call-Info header without a purpose parameter.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://voip.null.ro/cgi-bin/cvsweb.cgi/yate/modules/ysipchan.cpp | third party advisory issue tracking |
http://www.securityfocus.com/archive/1/467289/100/200/threaded | mailing list third party advisory vdb entry |
http://securityreason.com/securityalert/2716 | third party advisory exploit |
http://www.securityfocus.com/bid/23746 | third party advisory vdb entry |