CVE-2006-5444

Source
https://cve.org/CVERecord?id=CVE-2006-5444
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2006-5444.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2006-5444
Downstream
Published
2006-10-23T17:07:00Z
Modified
2026-04-10T03:38:36Z
Summary
[none]
Details

Integer overflow in the get_input function in the Skinny channel driver (chan_skinny.c) in Asterisk 1.0.x before 1.0.12 and 1.2.x before 1.2.13, as used by Cisco SCCP phones, allows remote attackers to execute arbitrary code via a certain dlen value that passes a signed integer comparison and leads to a heap-based buffer overflow.

References

Affected packages