Advertisement
Promo

Network management Toolkit in association with http://ad.doubleclick.net/clk;217618582;14453422;e?http://www.citrix.com/lang/English/lp/lp_1688615.asp

VoIP holes remain open

Patrick Gray ZDNet Australia

Published: 16 Jan 2004 10:00 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft is still investigating which of its products are vulnerable to a bug in its implementation of the H.323 voice over IP (VoIP) standard.

While the company has patched its Internet Security and Acceleration server software against the glitch, it has conceded that users of the company's NetMeeting software are probably vulnerable to buffer overflow bugs found in implementations of the protocol that could allow a remote attacker to take control of affected systems.

Microsoft's security program manager at the company's security response centre, Stephen Toulouse, told ZDNet Australia that "it's hard to say" how many of its users are still using NetMeeting -- however, the company is currently looking at the software to assess its potential vulnerability to the H.323 bug.

"Because NetMeeting implements H.323, the likelihood is yes, it's vulnerable," he said by phone from the US.

NetMeeting, which still ships with Windows XP -- albeit without a short-cut to the program installed by default -- serves primarily as communication software that allows users to hold audio and video conferencing sessions over the Internet. However, some system administrators have been known to use NetMeeting's remote administration capabilities to manage and configure systems over networks.

"It has been supplanted by a number of technologies," Tolouse said. "[But] I'm sure there are people still out there using it... we'll do whatever we need to do to protect those customers."

The H.323 flaw has affected a large number of vendors. The security bug, which was found by researchers at the University of Oulu in Finland, was discovered in a widely replicated implementation of the H.323 protocol, which meant the bug was effectively replicated in most incarnations of the protocol.

"It's one of those cases where security researchers found a flaw in the implementation of a protocol, and then anyone who had picked up on it or was adhering to that protocol was impacted by it," Tolouse said.

When asked if the case was similar to that of the discovery of flaws in a commonly used SNMP implementation in March, 2002, which affected a seemingly endless list of vendors, Tolouse said the "cases aren't that dissimilar at all," and pointed out that the University of Oulu also found that bug.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
43 out of 112 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:




Related Citrix Resources

Achieving the lowest server virtualization TCO

Consolidation through server virtualization is a powerful agent for datacenter change, but...

Achieving the lowest server virtualization Total Cost of Ownership

Consolidation through server virtualization is a powerful agent for datacenter change, but...

Citrix XenDesktop: The Best Desktop Delivery System For Today's Demanding Business Needs

Whether you're considering your first virtual desktop solution or trying to salvage an existing...

Desktop Virtualization: A buyer's checklist

Desktop virtualization should do more than just move desktop management to the datacenter—its real...

Five reasons why you need Citrix Essentials for Hyper-V now

This paper explores common challenges associated with server virtualization deployments and the...

See All White Papers

Video icon

Video

On The Road Blog

Mobile spells relief in Palestine

by Jacob Korenblum Whether you’re a foreign aid worker or a local community member--and whether you’re in Iraq or Guatemala—crisis events often look the same: High levels of confusion... More

Post a comment

Satellites to the rescue

By Einar Bjorgo Imagine a few years back – cell phones were reserved for a selected few, you could still keep up with your e-mail inbox and official correspondence would go via... More

Post a comment

Android passes 20,000 apps mark

There are now more than 20,000 Android applications and games, according to statistics from a site that tracks the platform's marketplace. According to AndroLib, Google's open source... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters