SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow SecurityAlert Database

Arrow  Topic :

Nortel IP Phone forced re-authentication


Arrow  SecurityAlert : 3274
Arrow  CVE : CVE-2007-5640
Arrow  SecurityRisk : Medium  Security Risk Medium  (About)
Arrow  Remote Exploit : Yes
Arrow  Local Exploit : No
Arrow  Exploit Available : No
Arrow  Credit : Daniel Stirnimann
Arrow  Published : 23.10.2007

Arrow  Affected Software : Nortel IP Phone



Arrow  Advisory Content :  

#############################################################

#

# COMPASS SECURITY ADVISORY http://www.csnc.ch/

#

#############################################################

#

# Product: IP Phone

# Vendor: Nortel

# Subject: IP Phone forced re-authentication

# Risk: High

# Effect: Currently exploitable

# Author: Daniel Stirnimann (daniel.stirnimann (at) csnc (dot) ch)

# Date: October, 18th 2007

#

#############################################################

Introduction:

-------------

The UNIStim signalisation protocol is vulnerable against spoofed
re-authentication messages. A malicious user can send spoofed registration
messages to the server to which a UNIStim IP phone is connected. This can
force the legitimate IP phone into a situation where it must re-register

with the server to maintain service. A continuous stream of these messages
prevents the IP phone from properly registering.

Nortel has noted this as:

Title: DoS Potential Vulnerability - UNIStim IP Phone Forced to
Re-register

Number: 2007008385

http://support.nortel.com/go/main.jsp?cscat=SECUREADVISORY

Vulnerable:

-----------

Nortel IP Phone 1140E

IP Softphone 2050

and others.

See associated products on the Nortel advisory.

Vulnerability Management:

-------------------------

June 2007: Vulnerability found

June 2007: Nortel Security notified

October 2007: Nortel Advisory & Patches available

October 2007: Compass Security Information

Remediation:

------------

Follow the recommended actions for the affected systems, as identified in
the Nortel Advisory.

Technical Description:

----------------------

A malicious user can send a resume message to the signaling server to which
an IP phone is connected. The resume message is a UNIStim UDP datagram. In
order for the signaling server to detect which IP phone wants to resume
the

connection it reads the source IP address from the UDP datagram to identify
the client. That means we can send a spoofed resume UNIStim UDP datagram.

The server sends the new sequence number back to the IP phone. However,
because we spoofed the above message, we don't see the response. The effect
is that, the IP phone is out of sync with the server. During this time, the
IP phone can not take on or make any calls. As soon as the IP phone
realizes that it is out of sync (watchdog timeout

expired) it will re-authenticate against the signaling server. Note that if
the malicious user continues to send spoofed resume messages

the hard phone will not be able to go online.

Reference:

http://www.csnc.ch/static/advisory/secadvisorylist.html






Arrow  Feedback :

If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Alert

libc/fnmatch(3) DoS

Security Risk Medium- 2011-05-13

Allow attacker to denial of service apache 2.2.17 server

Apache RSS Apache Alert

» Apache HTTP Server Denial
   of Service Vulnerability

» Multiple Vendors
   libc/fnmatch(3) DoS (incl
   apache poc)

» Apache Continuum
   cross-site scripting
   vulnerability

» Apache Tomcat DoS
   Vulnerability

PHP RSS PHP Alert

» PHP Hashtables Denial of
   Service

» PHP 5.3.6 multiple null
   pointer dereference

» PHP 5.3.6 ZipArchive
   invalid use glob(3)

» libzip 0.9.3
   _zip_name_locate NULL
   Pointer Dereference (incl
   PHP 5.3.5)

ADT

Protect your family and valuables with Home Security Systems

Copyright © SecurityReason.com. All Rights Reserved.