Multiple format string vulnerabilities in the gm_main_window_flash_message function in Ekiga before 2.0.5 allow attackers to cause a denial of service and possibly execute arbitrary code via a crafted Q.931 SETUP packet.
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ekiga | Ekiga | * | 2.0.4 (including) |
Red Hat Enterprise Linux 5 | RedHat | ekiga-0:2.0.2-7.0.2 | * |
Ekiga | Ubuntu | dapper | * |
Ekiga | Ubuntu | devel | * |
Ekiga | Ubuntu | edgy | * |
Ekiga | Ubuntu | feisty | * |