CVE-2007-5690

Publication date 29 October 2007

Last updated 4 August 2025


Ubuntu priority

Negligible

Why this priority?

Description

Buffer overflow in sethdlc.c in the Asterisk Zaptel 1.4.5.1 might allow local users to gain privileges via a long device name (interface name) in the ifr_name field. NOTE: the vendor disputes this issue, stating that the application requires root access, so privilege boundaries are not crossed

Read the notes from the security team

Status

Package Ubuntu Release Status
zaptel 9.10 karmic Ignored
9.04 jaunty Ignored
8.10 intrepid Ignored
8.04 LTS hardy Ignored
7.10 gutsy Ignored end of life, was needed
7.04 feisty Ignored end of life, was needed
6.10 edgy Ignored end of life, was needed
6.06 LTS dapper Ignored end of life

Notes


fujitsu

Not a security vulnerability, as the attacker would need to run the code as root, so there are no privileges to gain.


mdeslaur

if it's not an issue, let's ignore this


Access our resources on patching vulnerabilities