Multiple format string vulnerabilities in the gm_main_window_flash_message function in Ekiga before 2.0.5 allow attackers to cause a denial of service and possibly execute arbitrary code via a crafted Q.931 SETUP packet.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade net-voip/ekiga. | Oct 30, 2017 | Feb 19, 2007 |
| Suse | — | Upgrade ekigaUpgrade suse-release | Feb 17, 2015 | Feb 19, 2007 |
| Ubuntu | — | Upgrade gnomemeetingUpgrade ekiga | Nov 8, 2024 | Feb 20, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub