Title : Cisco Unified CallManager CTL Provider and RIS Collector Code Execution Issues VUPEN ID : VUPEN/ADV-2007-2512 CVE ID : CVE-2006-5277 - CVE-2006-5278
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-07-12
Technical Description
Two vulnerabilities have been identified in Cisco Unified Communications Manager (CUCM), formerly CallManager, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system.
The first issue is caused by an off-by-one buffer overflow error in the Certificate Trust List (CTL) Provider service when processing malformed requests (port 2444/TCP), which could be exploited by remote unauthenticated attackers to crash an affected service or execute arbitrary code.
The second vulnerability is caused by a heap overflow error in the Real-Time Information Server (RIS) Data Collector service when processing malformed requests (port 2556/TCP), which could be exploited by remote unauthenticated attackers to crash an affected service or execute arbitrary code.