|
|
| |
The MultiVOIP voice over IP gateway provides "toll-free voice and fax communications over the Internet or Intranet. Occasionally MultiTech develops and licenses their VoIP Gateways and VoIP related stacks for inclusion in third party platforms".
A remote buffer overflow vulnerability has been discovered in MultiTech's MultiVOIP product line that may lead to remote code execution. |
| |
Credit:
The information has been provided by SecurityLab Research.
|
| |
Vulnerable Systems:
* MultiVOIP gateway versions prior to x.08
Immune Systems:
* MultiVOIP gateway versions x.08
The buffer overflow occurs in the SIP packet INVITE field with a string greater than 60 characters. Testing was performed on an embedded device with limited debug environment.
|
|
|
|
|
|
|
|