application.cgi in the Pingtel Xpressa handset running firmware 2.1.11.24 allows remote authenticated users to cause a denial of service (VxWorks OS crash) via a long HTTP GET request, possibly triggering a buffer overflow.
| Software | From | Fixed in |
|---|---|---|
| pingtel / xpressa | 2.0 | 2.0.x |
| pingtel / xpressa | 1.2.8 | 1.2.8.x |
| pingtel / xpressa | 1.2.7.4 | 1.2.7.4.x |
| pingtel / xpressa | 1.2.5 | 1.2.5.x |
| pingtel / xpressa | 2.0.1 | 2.0.1.x |
| pingtel / xpressa | 2.1.11.24 | 2.1.11.24.x |