Title : Cisco Products CTL Provider Remote Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2008-0171 CVE ID : CVE-2008-0027
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-01-17
Technical Description
A vulnerability has been identified in Cisco Unified CallManager and Unified Communications Manager, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system. This issue is caused by a heap overflow error in the CTL (Certificate Trust List) Provider service "CTLProvider.exe" (port 2444/TCP) when processing user-supplied data, which could be exploited by remote unauthenticated attackers to crash a vulnerable application or execute arbitrary code.