blog.donews.com
http://blog.donews.com/zwell/archive/2006/01/17/698810.aspx CVE-2006-0359
CounterPath eyeBeam 1.1 build 3010n - SIP Header Data Remote Buffer Overflow (1)
Record summary
CVE-2006-0359 has a selected CVSS score of 7.5; EIP currently links 2 catalogued exploits.
Description
Buffer overflow in CounterPath eyeBeam SIP Softphone allows remote attackers to (1) cause a denial of service (device crash) via SIP INVITE commands with a long header field name sent during startup and (2) cause a denial of service (device hang or crash) via SIP INVITE commands with a long header field name sent during a call.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBCounterPath eyeBeam 1.1 build 3010n - SIP Header Data Remote Buffer Overflow (1)ExploitDB exploitby ZwelLNot analyzed1 file
ExploitDBCounterPath eyeBeam 1.1 build 3010n - SIP Header Data Remote Buffer Overflow (2)ExploitDB exploitby ZwelLNot analyzed1 file
References
918516Third-party advisory
http://secunia.com/advisories/18516 354Third-party advisory
http://securityreason.com/securityalert/354 20060116 CounterPath eyeBeam Handing SIP header Vulnerabilitiesmailing list
http://www.securityfocus.com/archive/1/422009/100/0/threaded 20060921 Re: CounterPath eyeBeam Handing SIP header Vulnerabilitiesmailing list
http://www.securityfocus.com/archive/1/446573/100/0/threaded 16253vdb entry
http://www.securityfocus.com/bid/16253 ADV-2006-0259vdb entry
http://www.vupen.com/english/advisories/2006/0259 eyebeam-sip-header-bo(24181)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/24181 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2006-0359