The CERT Coordination Center on Thursday warned of numerous security
vulnerabilities in vendor implementations of Session Initiation Protocol
(SIP), a signaling protocol for Web conferencing, telephony, presence,
events notification and instant messaging.
A security
alert from CERT/CC said the vulnerabilities open the doors for an
attacker to gain unauthorized privileged access, cause denial-of-service
attacks, or cause unstable system behavior. www.cert.org/ietf/inch/docs/draft-ietf-inch-iodef-11.txt:: Danyliw Internet-Draft CERT/NetSA Intended status: A reference to a vulnerability, malware sample, advisory, or analysis of an attack technique. http://www.cert.org/ietf/inch/docs/draft-ietf-inch-iodef-11.txtHOME | CERT warns of attacks, new holes in Windows - Network World:: The CERT Coordination Center has received reports of widespread attacks using a recently disclosed security vulnerability and a previously unknown security hole in http://www.networkworld.com/news/2003/0801certwarns.htmlHOME |
It warned that text-based SIP (define) protocol, used primarily in
Voice-over IP telephony, instant messaging and other presence applications,
contained holes in the subset related to invite message. Tests on a
variety of popular SIP-enabled products detected "unexpected system behavior
and denial-of-services to remote code execution."
The Center recommended that SIP-enabled devices and services be disabled
until vendor patches are made available. "As a temporary measure, it may
be possible to limit the scope of these vulnerabilities by blocking access
to SIP devices and services at the network perimeter," CERT/CC said. Researcher: Vonage Vulnerable - Desktop Security News Analysis - Dark :: Disguised as the SIP server, an attacker can execute a variety of exploits, In a separate warning, Sipera also said this vulnerability might be used to http://www.darkreading.com/document.asp?doc_id=137450&f_src=darkreading_node_1585HOME |
SIP-enabled products from IPTel and Nortel Networks were found to be
vulnerable.
A Shift in Platform Choices Favors Java
Intel Hands Developers its Library Card
|