Heap-based Buffer Overflow Vulnerability in Cisco Unified Communications Manager
CVE-2006-5277
Currently unrated
Key Information:
- Vendor
Cisco
- Vendor
- CVE Published:
- 15 July 2007
What is CVE-2006-5277?
An off-by-one error in the Certificate Trust List (CTL) Provider service (CTLProvider.exe) of Cisco Unified Communications Manager prior to version 20070711 can be exploited by remote attackers. By sending a specially crafted packet, an attacker may trigger a heap-based buffer overflow, potentially allowing them to execute arbitrary code on the affected system. This vulnerability places users at risk and underscores the importance of keeping software updated.