CVE Vulnerabilities

CVE-2006-5444

Published: Oct 23, 2006 | Modified: Oct 17, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Integer overflow in the get_input function in the Skinny channel driver (chan_skinny.c) in Asterisk 1.0.x before 1.0.12 and 1.2.x before 1.2.13, as used by Cisco SCCP phones, allows remote attackers to execute arbitrary code via a certain dlen value that passes a signed integer comparison and leads to a heap-based buffer overflow.

Affected Software

Name Vendor Start Version End Version
Asterisk Digium 0.1.7 (including) 0.1.7 (including)
Asterisk Digium 0.1.8 (including) 0.1.8 (including)
Asterisk Digium 0.1.9 (including) 0.1.9 (including)
Asterisk Digium 0.1.9.1 (including) 0.1.9.1 (including)
Asterisk Digium 0.2 (including) 0.2 (including)
Asterisk Digium 0.3 (including) 0.3 (including)
Asterisk Digium 0.4 (including) 0.4 (including)
Asterisk Digium 0.7 (including) 0.7 (including)
Asterisk Digium 0.7.1 (including) 0.7.1 (including)
Asterisk Digium 0.7.2 (including) 0.7.2 (including)
Asterisk Digium 0.9 (including) 0.9 (including)
Asterisk Digium 1.0 (including) 1.0 (including)
Asterisk Digium 1.0.7 (including) 1.0.7 (including)
Asterisk Digium 1.0.8 (including) 1.0.8 (including)
Asterisk Digium 1.0.9 (including) 1.0.9 (including)
Asterisk Digium 1.0.10 (including) 1.0.10 (including)
Asterisk Digium 1.0.11 (including) 1.0.11 (including)
Asterisk Digium 1.2.6 (including) 1.2.6 (including)
Asterisk Digium 1.2.7 (including) 1.2.7 (including)
Asterisk Digium 1.2.8 (including) 1.2.8 (including)
Asterisk Digium 1.2.9 (including) 1.2.9 (including)
Asterisk Digium 1.2.10 (including) 1.2.10 (including)
Asterisk Digium 1.2.11 (including) 1.2.11 (including)
Asterisk Digium 1.2.12 (including) 1.2.12 (including)
Asterisk Digium 1.2_beta1 (including) 1.2_beta1 (including)
Asterisk Digium 1.2_beta2 (including) 1.2_beta2 (including)
Asterisk Ubuntu dapper *
Asterisk Ubuntu devel *
Asterisk Ubuntu edgy *
Asterisk Ubuntu feisty *

References