VYPR
Unrated severityNVD Advisory· Published Oct 23, 2006· Updated Apr 23, 2026

CVE-2006-5444

CVE-2006-5444

Description

Integer overflow in the get_input function in the Skinny channel driver (chan_skinny.c) in Asterisk 1.0.x before 1.0.12 and 1.2.x before 1.2.13, as used by Cisco SCCP phones, allows remote attackers to execute arbitrary code via a certain dlen value that passes a signed integer comparison and leads to a heap-based buffer overflow.

Affected products

26
  • Digium/Asterisk26 versions
    cpe:2.3:a:digium:asterisk:0.1.7:*:*:*:*:*:*:*+ 25 more
    • cpe:2.3:a:digium:asterisk:0.1.7:*:*:*:*:*:*:*
    • cpe:2.3:a:digium:asterisk:0.1.8:*:*:*:*:*:*:*
    • cpe:2.3:a:digium:asterisk:0.1.9:*:*:*:*:*:*:*
    • cpe:2.3:a:digium:asterisk:0.1.9.1:*:*:*:*:*:*:*
    • cpe:2.3:a:digium:asterisk:0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:digium:asterisk:0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:digium:asterisk:0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:digium:asterisk:0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:digium:asterisk:0.7.1:*:*:*:*:*:*:*
    • cpe:2.3:a:digium:asterisk:0.7.2:*:*:*:*:*:*:*
    • cpe:2.3:a:digium:asterisk:0.9:*:*:*:*:*:*:*
    • cpe:2.3:a:digium:asterisk:1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:digium:asterisk:1.0.10:*:*:*:*:*:*:*
    • cpe:2.3:a:digium:asterisk:1.0.11:*:*:*:*:*:*:*
    • cpe:2.3:a:digium:asterisk:1.0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:digium:asterisk:1.0.8:*:*:*:*:*:*:*
    • cpe:2.3:a:digium:asterisk:1.0.9:*:*:*:*:*:*:*
    • cpe:2.3:a:digium:asterisk:1.2.10:*:*:*:*:*:*:*
    • cpe:2.3:a:digium:asterisk:1.2.11:*:*:*:*:*:*:*
    • cpe:2.3:a:digium:asterisk:1.2.12:*:*:*:*:*:*:*
    • cpe:2.3:a:digium:asterisk:1.2.6:*:*:*:*:*:*:*
    • cpe:2.3:a:digium:asterisk:1.2.7:*:*:*:*:*:*:*
    • cpe:2.3:a:digium:asterisk:1.2.8:*:*:*:*:*:*:*
    • cpe:2.3:a:digium:asterisk:1.2.9:*:*:*:*:*:*:*
    • cpe:2.3:a:digium:asterisk:1.2_beta1:*:*:*:*:*:*:*
    • cpe:2.3:a:digium:asterisk:1.2_beta2:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

19

News mentions

0

No linked articles in our index yet.