First published: Sun Jul 15 2007(Updated: )
Integer overflow in the Real-Time Information Server (RIS) Data Collector service (RisDC.exe) in Cisco Unified Communications Manager (CUCM, formerly CallManager) before 20070711 allow remote attackers to execute arbitrary code via crafted packets, resulting in a heap-based buffer overflow.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco CallManager Express | =5.0 | |
Cisco CallManager Express | >=3.3<=3.3\(5\)sr2 | |
Cisco CallManager Express | >=4.1<=4.1\(3\)sr4 | |
Cisco CallManager Express | >=4.2<=4.2\(3\)sr1 | |
Cisco Unified Communications Manager | >=4.3<=4.3\(1\) | |
Cisco CallManager Express | >=5.1<=5.1\(2\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5278 is classified as a critical vulnerability due to potential remote code execution.
To fix CVE-2006-5278, upgrade Cisco Unified Communications Manager to a version that addresses this integer overflow vulnerability.
CVE-2006-5278 allows remote attackers to execute arbitrary code through crafted packets, potentially compromising the entire system.
CVE-2006-5278 affects Cisco Unified Communications Manager versions before 20070711 including 3.3, 4.1, 4.2, and 5.1.
To determine vulnerability to CVE-2006-5278, check if your version of Cisco Unified Communications Manager is older than the fixed release date of 20070711.