7.5

CVE-2006-5444

Exploit

Integer overflow in the get_input function in the Skinny channel driver (chan_skinny.c) in Asterisk 1.0.x before 1.0.12 and 1.2.x before 1.2.13, as used by Cisco SCCP phones, allows remote attackers to execute arbitrary code via a certain dlen value that passes a signed integer comparison and leads to a heap-based buffer overflow.

Data is provided by the National Vulnerability Database (NVD)
DigiumAsterisk Version0.1.7
DigiumAsterisk Version0.1.8
DigiumAsterisk Version0.1.9
DigiumAsterisk Version0.1.9.1
DigiumAsterisk Version0.2
DigiumAsterisk Version0.3
DigiumAsterisk Version0.4
DigiumAsterisk Version0.7
DigiumAsterisk Version0.7.1
DigiumAsterisk Version0.7.2
DigiumAsterisk Version0.9
DigiumAsterisk Version1.0
DigiumAsterisk Version1.0.7
DigiumAsterisk Version1.0.8
DigiumAsterisk Version1.0.9
DigiumAsterisk Version1.0.10
DigiumAsterisk Version1.0.11
DigiumAsterisk Version1.2.6
DigiumAsterisk Version1.2.7
DigiumAsterisk Version1.2.8
DigiumAsterisk Version1.2.9
DigiumAsterisk Version1.2.10
DigiumAsterisk Version1.2.11
DigiumAsterisk Version1.2.12
DigiumAsterisk Version1.2_beta1
DigiumAsterisk Version1.2_beta2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 87.06% 0.994
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P