PT-2004-3519 · First Virtual Communications · Click To Meet Premier+3
Published
2004-12-31
·
Updated
2008-09-05
·
CVE-2004-2629
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
First Virtual Communications Click to Meet Express (when used with H.323 conferencing endpoints)
First Virtual Communications Click to Meet Premier
First Virtual Communications Conference Server
First Virtual Communications V-Gate
Description
The issue affects the H.323 protocol implementation, allowing remote attackers to cause a denial of service. This is demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.
Recommendations
For First Virtual Communications Click to Meet Express, consider disabling H.323 protocol support until a fix is available.
For First Virtual Communications Click to Meet Premier, restrict access to H.323 conferencing endpoints to minimize the risk of exploitation.
For First Virtual Communications Conference Server, avoid using the H.323 protocol for conferencing until the issue is resolved.
For First Virtual Communications V-Gate, temporarily disable the H.323 protocol implementation as a workaround.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Click To Meet Express
Click To Meet Premier
Conference Server
Vgate