First published: Fri Jul 14 2006(Updated: )
Buffer overflow in Cisco Unified CallManager (CUCM) 5.0(1) through 5.0(3a) allows remote attackers to execute arbitrary code via a long hostname in a SIP request, aka bug CSCsd96542.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco CallManager Express | =5.0\(1\) | |
Cisco CallManager Express | =5.0\(2\) | |
Cisco CallManager Express | =5.0\(3\) | |
Cisco CallManager Express | =5.0\(3a\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3594 is classified as a critical vulnerability due to the potential for remote code execution.
To fix CVE-2006-3594, upgrade Cisco Unified CallManager to a version beyond 5.0(3a) that does not contain this vulnerability.
CVE-2006-3594 affects Cisco Unified CallManager versions 5.0(1) to 5.0(3a).
CVE-2006-3594 facilitates remote code execution via a buffer overflow triggered by a long hostname in a SIP request.
Yes, CVE-2006-3594 can be exploited remotely by attackers sending specially crafted SIP requests.