SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#749342

Multiple vulnerabilities in H.323 implementations

Overview

A number of vulnerabilities have been discovered in various implementations of the multimedia telephony protocols H.323 and H.225. Voice over Internet Protocol (VoIP) and video conferencing equpiment and software can use these protocols to interoperate over a variety of computer networks. The majority of the vulnerabilities discovered are limited to denial of service impacts; however, several may allow unauthorized code execution.

I. Description

The U.K. National Infrastructure Security Co-ordination Center (NISCC) has reported multiple vulnerabilities in different vendor implementations of the multimedia telephony protocols H.323 and H.225. H.323 and H.225 are international standard protocols, published by the International Telecommunications Union, used to facilitate communication among telephony and multimedia systems. An example of such a system includes VoIP or video-conferencing equipment and software deployed on a network or computer. Sending an exceptional ASN.1 element to a vulnerable telephony component that cannot handle it may cause the application or system behavior to become unpredictable.

A test suite developed by NISCC has exposed vulnerabilities in a variety of H.323/H.225 implementations. While most of these vulnerabilities exist in ASN.1 parsing routines, some vulnerabilities may occur elsewhere. Due to the general lack of specific vulnerability information, this document covers multiple vulnerabilities in different H.323/H.225 implementations. Information about individual vendors is available in the Systems Affected section.

The U.K. National Infrastructure Security Co-ordination Centre is tracking this vulnerability as NISCC/006489/H.323.

II. Impact

The impacts associated with these vulnerabilities include denial of service, and potential execution of arbitrary code.

III. Solution

Patch or Upgrade


Apply a patch or upgrade as appropriate. Information about specific vendors is available in the Systems Affected section of this document.
One potential workaround includes making sure ports 1720/tcp and 1720/udp are blocked on network perimeters.

Systems Affected

VendorStatusDate NotifiedDate Updated
3ComUnknown2004-01-12
AlcatelUnknown2004-01-122004-01-30
Apple Computer, Inc.Not Vulnerable2004-01-122004-01-13
AT&TUnknown2004-01-13
AvayaUnknown2004-01-122004-01-13
Berkeley Software Design, Inc.Unknown2004-01-13
BorderwareUnknown2004-01-13
Check PointVulnerable2004-01-122004-01-30
Cisco Systems, Inc.Vulnerable2004-01-122004-01-13
ClavisterNot Vulnerable2004-01-122004-01-30
Computer AssociatesUnknown2004-01-13
CyberguardNot Vulnerable2004-01-13
D-Link SystemsUnknown2004-01-13
Debian LinuxUnknown2004-01-13
EMC CorporationUnknown2004-01-13
EngardeUnknown2004-01-13
eSoftNot Vulnerable2004-01-122004-01-13
Extreme NetworksUnknown2004-01-13
F5 Networks, Inc.Unknown2004-01-13
Foundry Networks Inc.Not Vulnerable2004-01-122004-01-30
FreeBSD, Inc.Unknown2004-01-13
FujitsuUnknown2004-01-122004-01-30
Global Technology AssociatesUnknown2004-01-13
Hewlett-Packard CompanyVulnerable2004-01-122004-04-05
HitachiNot Vulnerable2004-01-122004-01-13
IBM-zSeriesUnknown2004-01-13
IBM eServerUnknown2004-01-13
Ingrian Networks, Inc.Unknown2004-01-13
IntelVulnerable2004-01-122004-02-27
IntotoUnknown2004-01-13
Juniper Networks, Inc.Unknown2004-01-13
LachmanUnknown2004-01-13
LinksysUnknown2004-01-13
Lotus SoftwareUnknown2004-01-13
Lucent TechnologiesUnknown2004-01-122004-01-13
Mandriva, Inc.Unknown2004-01-13
Mandriva, Inc.Unknown2004-01-13
Microsoft CorporationVulnerable2004-01-122004-01-13
Mitel NetworksUnknown2004-02-10
MontaVista Software, Inc.Unknown2004-01-13
Multi-Tech Systems Inc.Unknown2004-01-13
NEC CorporationUnknown2004-01-13
NetBSDNot Vulnerable2004-01-122004-01-13
NetfilterUnknown2004-01-13
NetScreenNot Vulnerable2004-01-122004-01-30
Network ApplianceUnknown2004-01-13
NokiaUnknown2004-01-13
Nortel Networks, Inc.Vulnerable2004-01-122004-01-13
Novell, Inc.Unknown2004-01-13
Objective Systems Inc.Not Vulnerable2004-01-13
OpenBSDUnknown2004-01-13
Openwall GNU/*/LinuxUnknown2004-01-13
Oracle CorporationUnknown2004-01-13
PolycomVulnerable2009-07-29
RadVisionVulnerable2004-01-13
Red Hat, Inc.Not Vulnerable2004-01-122004-01-13
Riverstone NetworksUnknown2004-01-13
Secure Computing CorporationUnknown2004-01-13
SecureWorksUnknown2004-01-13
Sequent Computer Systems, Inc.Unknown2004-01-13
Sony CorporationUnknown2004-01-122004-01-30
StonesoftUnknown2004-01-13
Sun Microsystems, Inc.Not Vulnerable2004-01-122004-01-14
SUSE LinuxUnknown2004-01-13
Symantec CorporationNot Vulnerable2004-01-122004-01-13
TandBergVulnerable2004-01-13
Tumbleweed Communications Corp.Not Vulnerable2004-01-13
TurboLinuxUnknown2004-01-13
uniGoneNot Vulnerable2004-01-13
UnisysUnknown2004-01-13
WatchGuardUnknown2004-01-13
Wind River Systems, Inc.Unknown2004-01-13
WirexUnknown2004-01-13
XeroxNot Vulnerable2004-01-122004-01-15
ZyXELUnknown2004-01-13

References

http://www.kb.cert.org/vuls/id/927278
http://www.kb.cert.org/vuls/id/428230
http://www.uniras.gov.uk/vuls/2004/006489/h323.htm
http://www.itu.int/itudoc/itu-t/rec/h/h225-0.html
http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/h2250v4/index.html

Credit

The CERT Coordination Center thanks the NISCC Vulnerability Management Team and the University of Oulu Security Programming Group OUSPG for coordinating the discovery and release of the technical details of this issue.

This document was written Jeffrey S. Havrilla based on information from NISCC.

Other Information

Date Public:2003-01-13
Date First Published:2004-01-13
Date Last Updated:2009-07-29
CERT Advisory:CA-2004-01
CVE-ID(s):CVE-2003-0819
NVD-ID(s):CVE-2003-0819
US-CERT Technical Alerts: 
Metric:13.67
Document Revision:42

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2004 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader