CVE Database
/

CVE-2006-5277

Back to search

CVE-2006-5277

Published: Jul 15, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Off-by-one error in the Certificate Trust List (CTL) Provider service (CTLProvider.exe) in Cisco Unified Communications Manager (CUCM, formerly CallManager) before 20070711 allow remote attackers to execute arbitrary code via a crafted packet that triggers a heap-based buffer overflow.

VendorProductVersions

n/a

n/a

affected
n/a

References

36122
vdb-entry
x_refsource_OSVDB
ADV-2007-2512
vdb-entry
x_refsource_VUPEN
26043
third-party-advisory
x_refsource_SECUNIA
24868
vdb-entry
x_refsource_BID
voip-filename-overflow(31437)
vdb-entry
x_refsource_XF
1018369
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now