First published: Sun Jul 15 2007(Updated: )
Off-by-one error in the Certificate Trust List (CTL) Provider service (CTLProvider.exe) in Cisco Unified Communications Manager (CUCM, formerly CallManager) before 20070711 allow remote attackers to execute arbitrary code via a crafted packet that triggers a heap-based buffer overflow.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified CallManager | =5.0 | |
Cisco Unified CallManager | >=3.3<=3.3\(5\)sr2 | |
Cisco Unified CallManager | >=4.1<=4.1\(3\)sr4 | |
Cisco Unified CallManager | >=4.2<=4.2\(3\)sr1 | |
Cisco Unified Communications Manager | >=4.3<=4.3\(1\) | |
Cisco Unified Communications Manager | >=5.1<=5.1\(1\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.