by Steve Taylor and Larry Hettick

Is the H.323 vulnerability a showstopper?

Opinion
Jan 26, 20042 mins

* Analysis of the security hole in H.323 implementations

Earlier this month, the National Infrastructure Security Coordination Centre in the U.K. advised that implementations of the H.323 protocol are vulnerable to denial-of-service attacks and could even allow attackers to exploit a buffer overflow to execute code of their own.

This potential exploit gained even more attention when it was noted that voice-over-IP systems from Cisco, Nortel and Avaya, among others, could be affected.

Before SIP-lovers get too smug in the SIP-vs.-H.323 controversy, it’s important to realize that, as Cisco points out in its response to this advisory, the vulnerability “may include devices configured for Session Initiation Protocol (SIP) or Media Gateway Control Protocol (MGCP), since support for these protocols can enable support for H.323.”

Unfortunately, this vulnerability gives yet another bit of ammunition for the anti-VoIP crowd. After all, security is a major concern, and this is yet another example of a security flaw being exposed.

But overall, we don’t see this as being earthshaking news. In fact, it’s not really even surprising. And even though the major emphasis is on VoIP, the flaw also affects a number of other systems.

In fact we see some good news as well. Maybe it’s a sad commentary on the state of networking, but our industry has become quite adept at patching systems. All of the major players had advisories with patches and/or workarounds within a couple of days. Most importantly, we’re not aware of any reports of this vulnerability actually having been exploited in a production environment.