CVE-2006-0359
CounterPath eyeBeam SIP Softphone - Denial of Service via Long SIP INVITE Header Field
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2006-0359. PoCs published by ZwelL.
AI-analyzed exploit summary This exploit demonstrates a buffer overflow vulnerability in CounterPath eyeBeam by sending a maliciously crafted SIP INVITE request with an overly long 'From' header. The PoC sends multiple UDP packets to trigger a denial-of-service (DoS) condition, potentially leading to remote code execution.
Description
Buffer overflow in CounterPath eyeBeam SIP Softphone allows remote attackers to (1) cause a denial of service (device crash) via SIP INVITE commands with a long header field name sent during startup and (2) cause a denial of service (device hang or crash) via SIP INVITE commands with a long header field name sent during a call.
Exploits (2)
This exploit demonstrates a buffer overflow vulnerability in CounterPath eyeBeam by sending a maliciously crafted SIP INVITE request with an overly long 'From' header. The PoC sends multiple UDP packets to trigger a denial-of-service (DoS) condition, potentially leading to remote code execution.
This exploit targets a buffer overflow vulnerability in CounterPath eyeBeam (eStara Softphone) by sending a maliciously crafted SIP INVITE packet. The overflow is triggered by an excessively long 'a=' field in the SDP section, potentially leading to remote code execution.