Hi list,

This issue I have raised earlier but did not get any response.I am not sure
whether its right place to report this issue or not

http://qutecom.org/ticket/399

QuteCom crashes if a phone number of more than 5000 characters is dialed
from the application.
This bug in Qutecom v2.2.1 is caused due to a boundary error in the
processing of too long phone number.This heap buffer overflow bug can be
triggred by dialing a more than 5000 character set as phone number form the
soft phone. *To trigger this bug the application must be connected to a
VOIP/SIP server.*
I have tested this issue on Windows XP SP2 and used TrixBox server as PBX
Phone System.

*As this issue is related to HEAP corruption so this may be an exploitable
bug.*

Tested with latest stable release:

http://trac.qutecom.org/downloads/QuteCom-2.2.1-setup-release.exe

For more technical details revert back.

-- 
Cheers,
Debasish
http://www.debasish.in/
_______________________________________________
QuteCom-dev mailing list
[email protected]
http://lists.qutecom.org/mailman/listinfo/qutecom-dev

Reply via email to