Unrated severityNVD Advisory· Published Oct 8, 2007· Updated Apr 23, 2026
CVE-2007-4924
CVE-2007-4924
Description
The Open Phone Abstraction Library (opal), as used by (1) Ekiga before 2.0.10 and (2) OpenH323 before 2.2.4, allows remote attackers to cause a denial of service (crash) via an invalid Content-Length header field in Session Initiation Protocol (SIP) packets, which causes a \0 byte to be written to an "attacker-controlled address."
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
22- mail.gnome.org/archives/ekiga-list/2007-September/msg00103.htmlnvdPatch
- secunia.com/advisories/27118nvdPatchVendor Advisory
- secunia.com/advisories/27128nvdPatchVendor Advisory
- secunia.com/advisories/27129nvdPatchVendor Advisory
- www.redhat.com/support/errata/RHSA-2007-0957.htmlnvdPatch
- lists.opensuse.org/opensuse-security-announce/2007-10/msg00006.htmlnvd
- openh323.cvs.sourceforge.net/openh323/opal/src/sip/sippdu.cxxnvd
- osvdb.org/41637nvd
- secunia.com/advisories/27271nvd
- secunia.com/advisories/27524nvd
- secunia.com/advisories/28380nvd
- www.mandriva.com/security/advisoriesnvd
- www.s21sec.com/avisos/s21sec-037-en.txtnvd
- www.securityfocus.com/archive/1/482120/30/4500/threadednvd
- www.securityfocus.com/bid/25955nvd
- www.securitytracker.com/idnvd
- www.ubuntu.com/usn/usn-562-1nvd
- www.vupen.com/english/advisories/2007/3413nvd
- www.vupen.com/english/advisories/2007/3414nvd
- bugzilla.redhat.com/show_bug.cginvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11398nvd
- www.exploit-db.com/exploits/9240nvd
News mentions
0No linked articles in our index yet.