CVE-2007-5690

high

Description

Buffer overflow in sethdlc.c in the Asterisk Zaptel 1.4.5.1 might allow local users to gain privileges via a long device name (interface name) in the ifr_name field. NOTE: the vendor disputes this issue, stating that the application requires root access, so privilege boundaries are not crossed

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/37335

http://www.securitytracker.com/id?1018885

http://www.securityfocus.com/bid/26160

http://www.securityfocus.com/archive/1/483481/100/0/threaded

http://www.securityfocus.com/archive/1/482597/100/0/threaded

http://www.eleytt.com/advisories/eleytt_ZAPTEL.pdf

http://securityreason.com/securityalert/3319

http://downloads.digium.com/pub/asa/AST-2007-024.html

Details

Source: Mitre, NVD

Published: 2007-10-29

Updated: 2024-04-11

Risk Information

CVSS v2

Base Score: 4.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High