CVE-2008-5872
https://notcve.org/view.php?id=CVE-2008-5872
Multiple unspecified vulnerabilities in the UNIStim File Transfer Protocol (UFTP) processing in IP Client Manager (IPCM) in Nortel Multimedia Communication Server (MSC) 5100 3.0.13 allow remote attackers to cause a denial of service (device outage) via a UFTP message that has a negative block size or other crafted Connection Details values. Múltiples vulnerabilidades no especificadas en el Protocolo de Transferencia de Ficheros UNIStim (UFTP) procesando en IP Client Manager (IPCM) en Nortel Multimedia Communication Server (MSC) 5100 v3.0.13 permite a atacantes remotos provocar una denegación de servicio (agotamiento de dispositivo) a través de un mensaje UFTP que tiene un tamaño bloqueado negativo u otros valores Connection Details manipulados. • http://secunia.com/advisories/32203 http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=774845 http://voipshield.com/research-details.php?id=120 http://www.securityfocus.com/bid/31633 http://www.vupen.com/english/advisories/2008/2779 https://exchange.xforce.ibmcloud.com/vulnerabilities/45751 • CWE-20: Improper Input Validation •
CVE-2008-5871
https://notcve.org/view.php?id=CVE-2008-5871
Nortel Multimedia Communication Server (MSC) 5100 3.0.13 does not verify credentials during call placement, which allows remote attackers to spoof and redirect VoIP calls, possibly related to the snoop command. Nortel Multimedia Communication Server (MSC) 5100 v3.0.13 no verifica credenciales durante la llamada de reemplazo, lo cual permite a atacantes remotos envenenar y redireccionar llamadas VoIP, posiblemente relacionado con el comando "snoop". • http://secunia.com/advisories/32203 http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=775223 http://voipshield.com/research-details.php?id=119 http://www.securityfocus.com/bid/31640 http://www.vupen.com/english/advisories/2008/2779 https://exchange.xforce.ibmcloud.com/vulnerabilities/45752 • CWE-255: Credentials Management Errors •