Off-by-one error in the Certificate Trust List (CTL) Provider service (CTLProvider.exe) in Cisco Unified Communications Manager (CUCM, formerly CallManager) before 20070711 allow remote attackers to execute arbitrary code via a crafted packet that triggers a heap-based buffer overflow.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Unified_callmanager | Cisco | 3.3 (including) | 3.3(5)sr2 (including) |
Unified_callmanager | Cisco | 4.1 (including) | 4.1(3)sr4 (including) |
Unified_callmanager | Cisco | 4.2 (including) | 4.2(3)sr1 (including) |
Unified_callmanager | Cisco | 5.0 (including) | 5.0 (including) |
Unified_communications_manager | Cisco | 4.3 (including) | 4.3(1) (including) |
Unified_communications_manager | Cisco | 5.1 (including) | 5.1(1) (including) |