Partner With Us
























CERT Warns of SIP Vulnerabilities

The text-based signaling protocol contains numerous security bugs that could lead to denial-of-service attacks.

February 21, 2003
By Ryan Naraine: More stories by this author:

The CERT Coordination Center on Thursday warned of numerous security vulnerabilities in vendor implementations of Session Initiation Protocol (SIP), a signaling protocol for Web conferencing, telephony, presence, events notification and instant messaging.

A security alert from CERT/CC said the vulnerabilities open the doors for an attacker to gain unauthorized privileged access, cause denial-of-service attacks, or cause unstable system behavior.

It warned that text-based SIP (define) protocol, used primarily in Voice-over IP telephony, instant messaging and other presence applications, contained holes in the subset related to invite message. Tests on a variety of popular SIP-enabled products detected "unexpected system behavior and denial-of-services to remote code execution."

The Center recommended that SIP-enabled devices and services be disabled until vendor patches are made available. "As a temporary measure, it may be possible to limit the scope of these vulnerabilities by blocking access to SIP devices and services at the network perimeter," CERT/CC said.

SIP-enabled products from IPTel and Nortel Networks were found to be vulnerable.







Developer Archives | 7 Day InternetNews Summary | Contact Ryan Naraine | Back to top

Add internetnews.com
to your browser search box.

IE 7 | Firefox 2.0 | Firefox 1.5.x
Receive news
via our XML/RSS:
feed



More InternetNews.com


Hardware Software Mobility Web Content
Search Government Developer Business
Storage E-Commerce Networking Security



internet.commediabistro.comJusttechjobs.comGraphics.com

Search:

WebMediaBrands Corporate Info

Legal Notices, Licensing, Reprints, Permissions, Privacy Policy.
Advertise | Newsletters | Shopping | E-mail Offers | Freelance Jobs