CVE-2006-5278

CWE-119Buffer Overflow4 documents4 sources
Severity
10.0CRITICAL
EPSS
10.1%
top 6.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 15
Latest updateMay 1

Description

Integer overflow in the Real-Time Information Server (RIS) Data Collector service (RisDC.exe) in Cisco Unified Communications Manager (CUCM, formerly CallManager) before 20070711 allow remote attackers to execute arbitrary code via crafted packets, resulting in a heap-based buffer overflow.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages2 packages

NVDcisco/unified_callmanager3.33.3\(5\)sr2+4

Patches

🔴Vulnerability Details

2
GHSA
GHSA-578w-ff3h-hrqq: Integer overflow in the Real-Time Information Server (RIS) Data Collector service (RisDC2022-05-01
CVEList
CVE-2006-5278: Integer overflow in the Real-Time Information Server (RIS) Data Collector service (RisDC2007-07-15

📋Vendor Advisories

1
Cisco
Cisco Unified Communications Manager Overflow Vulnerabilities2007-07-11
CVE-2006-5278 (CRITICAL CVSS 10) | Integer overflow in the Real-Time I | cvebase.io