First published: Sun Jul 15 2007(Updated: )
Off-by-one error in the Certificate Trust List (CTL) Provider service (CTLProvider.exe) in Cisco Unified Communications Manager (CUCM, formerly CallManager) before 20070711 allow remote attackers to execute arbitrary code via a crafted packet that triggers a heap-based buffer overflow.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco CallManager Express | =5.0 | |
Cisco CallManager Express | >=3.3<=3.3\(5\)sr2 | |
Cisco CallManager Express | >=4.1<=4.1\(3\)sr4 | |
Cisco CallManager Express | >=4.2<=4.2\(3\)sr1 | |
Cisco Unified Communications Manager | >=4.3<=4.3\(1\) | |
Cisco Unified Communications Manager | >=5.1<=5.1\(1\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5277 has been classified as a critical vulnerability due to its potential to allow remote code execution.
To fix CVE-2006-5277, upgrade Cisco Unified Communications Manager to a version that is patched against this vulnerability.
CVE-2006-5277 affects several versions of Cisco Unified Communications Manager, specifically versions prior to 20070711.
Yes, CVE-2006-5277 can be exploited remotely by sending crafted packets to the vulnerable service.
CVE-2006-5277 involves an off-by-one error that leads to a heap-based buffer overflow.