Heap-based Buffer Overflow Vulnerability in Cisco Unified Communications Manager
CVE-2006-5277

Currently unrated

Key Information:

Vendor
Cisco
Vendor
CVE Published:
15 July 2007

Summary

An off-by-one error in the Certificate Trust List (CTL) Provider service (CTLProvider.exe) of Cisco Unified Communications Manager prior to version 20070711 can be exploited by remote attackers. By sending a specially crafted packet, an attacker may trigger a heap-based buffer overflow, potentially allowing them to execute arbitrary code on the affected system. This vulnerability places users at risk and underscores the importance of keeping software updated.

References

EPSS Score

5% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.