lib/engine/components/opal/opal-call.cpp in ekiga before 4.0.0 allows remote attackers to cause a denial of service (crash) via an OPAL connection with a party name that contains invalid UTF-8 strings.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "ekiga",
"binary_version": "4.0.1-6"
},
{
"binary_name": "ekiga-dbg",
"binary_version": "4.0.1-6"
},
{
"binary_name": "ekiga-dbgsym",
"binary_version": "4.0.1-6"
},
{
"binary_name": "ekiga-plugin-evolution",
"binary_version": "4.0.1-6"
},
{
"binary_name": "ekiga-plugin-evolution-dbgsym",
"binary_version": "4.0.1-6"
}
]
}