The SIP component in Ingate Firewall before 4.6.0 and SIParator before 4.6.0, when Remote NAT Traversal is employed, does not properly perform user registration and message distribution, which might allow remote authenticated users to receive messages intended for other users.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://osvdb.org/42172 | vdb entry |
http://secunia.com/advisories/27688 | third party advisory vendor advisory |
http://www.securityfocus.com/bid/26486 | vdb entry |
http://www.ingate.com/relnote-460.php |