CVE-2007-4897

NameCVE-2007-4897
Descriptionpwlib, as used by Ekiga 2.0.5 and possibly other products, allows remote attackers to cause a denial of service (application crash) via a long argument to the PString::vsprintf function, related to a "memory management flaw". NOTE: this issue was originally reported as being in the SIPURL::GetHostAddress function in Ekiga (formerly GnomeMeeting).
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDTSA-94-1
Debian Bugs454133, 454139

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
pwlibsourcesarge1.8.4-1+sarge1.1
pwlibsourceetch1.10.2-2+etch1
pwlibsourcelenny1.10.7~dfsg1-4+lenny1DTSA-94-1
pwlibsource(unstable)1.10.10-1.1low454133
pwlib-titansourcelenny1.11.2-1+lenny1DTSA-94-1
pwlib-titansource(unstable)1.11.2-1.1low454139

Search for package or bug name: Reporting problems