PT-2008-6324 · Microsoft · Ge Communicator+1

Praveen Darshanam

·

Publicado

2008-11-20

·

Atualizado

2024-10-15

·

CVE-2008-5180

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Microsoft Communicator (affected versions not specified) Microsoft Office 2010 beta (affected versions not specified)
Description The issue allows remote attackers to cause a denial of service, resulting in memory consumption, via a large number of SIP INVITE requests. This triggers the creation of many sessions.
Recommendations For Microsoft Communicator, consider restricting the number of incoming SIP INVITE requests to prevent excessive session creation until a fix is available. For Microsoft Office 2010 beta, restrict access to the Communicator component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Allocation of Resources Without Limits

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-5180

Produtos afetados

Ge Communicator
Office 2010