CVE-2006-5278: Buffer Overflow
Integer overflow in the Real-Time Information Server (RIS) Data Collector service (RisDC.exe) in Cisco Unified Communications Manager (CUCM, formerly CallManager) before 20070711 allow remote attackers to execute arbitrary code via crafted packets, resulting in a heap-based buffer overflow.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5278?
CVE-2006-5278 is classified as a critical vulnerability due to potential remote code execution.
How do I fix CVE-2006-5278?
To fix CVE-2006-5278, upgrade Cisco Unified Communications Manager to a version that addresses this integer overflow vulnerability.
What kind of attacks are possible due to CVE-2006-5278?
CVE-2006-5278 allows remote attackers to execute arbitrary code through crafted packets, potentially compromising the entire system.
Which versions of Cisco Unified Communications Manager are affected by CVE-2006-5278?
CVE-2006-5278 affects Cisco Unified Communications Manager versions before 20070711 including 3.3, 4.1, 4.2, and 5.1.
How can I determine if I am vulnerable to CVE-2006-5278?
To determine vulnerability to CVE-2006-5278, check if your version of Cisco Unified Communications Manager is older than the fixed release date of 20070711.