TANDBERG Products H.323 Protocol Implementation Vulnerabilities
SECUNIA ADVISORY ID:
SA10934
VERIFY ADVISORY:
http://secunia.com/advisories/10934/
CRITICAL:
Moderately critical
IMPACT:
DoS
WHERE:
From remote
OPERATING SYSTEM:
TANDBERG Codec E3.x
TANDBERG Codec B8.x
DESCRIPTION:
TANDBERG has acknowledged that some products are affected by the recently reported vulnerabilities in various vendors' H.323 protocol implementations.
The vulnerabilities are caused due to errors in the processing of H.225 messages over TCP. This can be exploited by malicious people to reboot an affected device by sending specially crafted messages to it (default port 1720/tcp).
SOLUTION:
Update to revision E3.1 or B.8.1.
For further details and links please click here to see the actual Secunia Advisory: http://secunia.com/advisories/10934/
