Description
The command line interface (CLI) in Cisco Unified CallManager (CUCM) 5.0(1) through 5.0(3a) allows local users to overwrite arbitrary files by redirecting a command's output to a file or folder, aka bug CSCse31704.
Affected products
- Cisco / unified_callmanager5.0(1) – 5.0(1)
- Cisco / unified_callmanager5.0(2) – 5.0(2)
- Cisco / unified_callmanager5.0(3) – 5.0(3)
- Cisco / unified_callmanager5.0(3a) – 5.0(3a)
References
- MISChttp://securitytracker.com/id?1016475
- MISChttp://www.securityfocus.com/bid/18952
- VENDOR_ADVISORYhttp://www.cisco.com/en/US/products/products_security_advisory09186a00806e0b9f.shtml
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2006/2774
- MISChttp://www.osvdb.org/27161
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/27690
- VENDOR_ADVISORYhttp://secunia.com/advisories/21030