SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow SecurityAlert Database

Arrow  Topic :

Nortel IP Phone forced re-authentication


Arrow  SecurityAlert : 3274
Arrow  CVE : CVE-2007-5640
Arrow  SecurityRisk : Medium  Security Risk Medium  (About)
Arrow  Remote Exploit : Yes
Arrow  Local Exploit : No
Arrow  Exploit Available : No
Arrow  Credit : Daniel Stirnimann
Arrow  Published : 23.10.2007

Arrow  Affected Software : Nortel IP Phone



Arrow  Advisory Content :  

#############################################################

#

# COMPASS SECURITY ADVISORY http://www.csnc.ch/

#

#############################################################

#

# Product: IP Phone

# Vendor: Nortel

# Subject: IP Phone forced re-authentication

# Risk: High

# Effect: Currently exploitable

# Author: Daniel Stirnimann (daniel.stirnimann (at) csnc (dot) ch)

# Date: October, 18th 2007

#

#############################################################

Introduction:

-------------

The UNIStim signalisation protocol is vulnerable against spoofed
re-authentication messages. A malicious user can send spoofed registration
messages to the server to which a UNIStim IP phone is connected. This can
force the legitimate IP phone into a situation where it must re-register

with the server to maintain service. A continuous stream of these messages
prevents the IP phone from properly registering.

Nortel has noted this as:

Title: DoS Potential Vulnerability - UNIStim IP Phone Forced to
Re-register

Number: 2007008385

http://support.nortel.com/go/main.jsp?cscat=SECUREADVISORY

Vulnerable:

-----------

Nortel IP Phone 1140E

IP Softphone 2050

and others.

See associated products on the Nortel advisory.

Vulnerability Management:

-------------------------

June 2007: Vulnerability found

June 2007: Nortel Security notified

October 2007: Nortel Advisory & Patches available

October 2007: Compass Security Information

Remediation:

------------

Follow the recommended actions for the affected systems, as identified in
the Nortel Advisory.

Technical Description:

----------------------

A malicious user can send a resume message to the signaling server to which
an IP phone is connected. The resume message is a UNIStim UDP datagram. In
order for the signaling server to detect which IP phone wants to resume
the

connection it reads the source IP address from the UDP datagram to identify
the client. That means we can send a spoofed resume UNIStim UDP datagram.

The server sends the new sequence number back to the IP phone. However,
because we spoofed the above message, we don't see the response. The effect
is that, the IP phone is out of sync with the server. During this time, the
IP phone can not take on or make any calls. As soon as the IP phone
realizes that it is out of sync (watchdog timeout

expired) it will re-authenticate against the signaling server. Note that if
the malicious user continues to send spoofed resume messages

the hard phone will not be able to go online.

Reference:

http://www.csnc.ch/static/advisory/secadvisorylist.html






Arrow  Feedback :

If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Alert

libc:fts_*() Multiple Denial of Service

Security Risk Medium- 2009-10-02

The fts functions are provided for traversing UNIX file hierarchies...

Apache RSS Apache Alert

» Apache 1.3.41 mod_proxy
   Integer overflow (code
   execution)

» Apache Tomcat 6.0.20 and
   5.5.28 unexpected file
   deletion in work
   directory

» Apache Tomcat 6.0.20 and
   5.5.28 insecure partial
   deploy after failed
   undeploy

» Apache Tomcat 6.0.20 and
   5.5.28 unexpected file
   deletion and/or
   alteration

PHP RSS PHP Alert

» PHP 5.2.12/5.3.1 Multiple
   Vulnerabilities

» PHP 5.2.11 libgd multiple
   vulnerabilities

» PHP 5.2.11 tempnam()
   safe_mode bypass

» PHP 5.3.0 5.2.11
   posix_mkfifo()
   open_basedir bypass

Copyright © SecurityReason.com. All Rights Reserved.