SUBSCRIBE TO TMCnet
TMCnet - World's Largest Communications and Technology Community

CHANNEL BY TOPICS


QUICK LINKS




Radware Issues Advisory for YATE Vulnerabilities that Can Disrupt VoIP Infrastructures

TMCnews Featured Article


May 02, 2007

Radware Issues Advisory for YATE Vulnerabilities that Can Disrupt VoIP Infrastructures

By Anuradha Shukla, TMCnet Contributor


The research team of Radware’s Security Operations Center has recently discovered a denial of service vulnerability in YATE (Yet Another Telephony Engine) release 1.1.0, a production-ready next-generation telephony engine.


As part of Radware Security Update Service (SUS) an immediate protection is available to safeguard customer infrastructures in advance of public disclosure of the flaw. A denial of service vulnerability is contained in the SIP channel module of YATE. Since no authentication is required to exploit this vulnerability by default, it allows spoofed UDP SIP messages to trigger the flaw.

According to a press release, disruption of the VoIP infrastructure can be caused by the exploitation of this vulnerability. On March 25, 2007, Radware Security Research Center notified YATE about the existence of a denial of service vulnerability in YATE release 1.1.0. YATE released a fix version 1.2.0 that addresses this vulnerability on April 16th. Radware released attack database protection against this vulnerability on April 29th and advisory was released on May 1.

With the release of attack database version 0006.0030.00 by RWID's 7334, 7338 and 7342, Radware DefensePro customers are protected against this vulnerability.

Radware, the global provider of integrated application delivery solutions, assures the full availability, maximum performance, and complete security of business-critical applications for more than 5,000 enterprises and carriers worldwide.

Radware was in news earlier this week for launching the first phase of its “Business-Smart Network” strategy with the acquisition of Covelight Systems.

Covelight Systems’ flagship Inflight product captures detailed, business events from Web transactions, to Radware’s comprehensive APSolute application delivery suite. The addition of this product will enable companies to quickly unleash the value of previously hard-to-access business-event intelligence taking place on the network.

Thanks to the real time access to this critical data, companies can now optimize their business processes, offer new products and services on-the-fly to customers, and halt identity theft or fraudulent online behavior without unwanted delay.

-------

Anuradha Shukla is a contributing editor for TMCnet, covering call centers, CRM and information technology. To see more of her articles, please visit her columnist page.

Don't forget to check out TMCnet’s White Paper Library, which provides a selection of in-depth information on relevant topics affecting the IP Communications industry. The library offers white papers, case studies and other documents which are free to registered users.

Also be sure to attend TMC’s (News - Alert) Communications Developer Conference to be held May 14-17, 2007 at the Hyatt Regency Santa Clara, Calif. Come learn how to build the next generation of IP-based communications products and services!







Technology Marketing Corporation

2 Trap Falls Road Suite 106, Shelton, CT 06484 USA
Ph: +1-203-852-6800, 800-243-6002

General comments: [email protected].
Comments about this site: [email protected].

STAY CURRENT YOUR WAY

© 2026 Technology Marketing Corporation. All rights reserved | Privacy Policy