Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2007-5690

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Asterisk Zaptel 1.4.5.1版本的sethdlc.c中存在缓冲区溢出。本地用户可以借助ifr_name字段的一个超长的驱动程序名(界面名),获得特权。

AI Predicted 1.9 Difficulty: Trivial EPSS 0.36% · P29
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2007-5690

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Buffer overflow in sethdlc.c in the Asterisk Zaptel 1.4.5.1 might allow local users to gain privileges via a long device name (interface name) in the ifr_name field. NOTE: the vendor disputes this issue, stating that the application requires root access, so privilege boundaries are not crossed
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Asterisk Zaptel 'sethdlc.c' 缓冲区溢出漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Asterisk Zaptel 1.4.5.1版本的sethdlc.c中存在缓冲区溢出。本地用户可以借助ifr_name字段的一个超长的驱动程序名(界面名),获得特权。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2007-5690

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2007-5690

登录查看更多情报信息。

Vendor Advisories for CVE-2007-5690 (5)

News Coverage for CVE-2007-5690 (1)

Other References for CVE-2007-5690 (2)

Same Patch Batch · n/a · 2007-10-29 · 55 CVEs total

CVE-2002-2351 Qualcomm Eudora文件附件欺骗漏洞
CVE-2007-5689 Sun Java SDK and JRE Runtime Environment Virtual Machine 远程特权提升漏洞
CVE-2002-2361 Yahoo即时通讯签名内容漏洞
CVE-2002-2364 PHP Ticket跨站脚本漏洞
CVE-2002-2363 HP-UX VJE.VJE-RUN默认路径修改漏洞
CVE-2002-2362 MyMarket Form_Header.PHP跨站脚本漏洞
CVE-2007-5688 phpBB 和 Invision Power Board Multi-Forums 'Directory.PHP' 多个SQL注入漏洞
CVE-2002-2354 Netgear FM114P无线防火墙TCP连接远程拒绝服务攻击漏洞
CVE-2002-2353 TFTPD32任意文件下载或上传漏洞
CVE-2002-2352 NeoSoft NeoBook 4 ActiveX控件任意文件类型包含漏洞
CVE-2002-2355 Netgear FM114P无线防火墙远程信息泄露漏洞
CVE-2002-2350 Zorum dbtreelistproperty_method.php z_user_show.php脚本注入漏洞
CVE-2002-2349 PHPBBMod PHPInfo信息泄露漏洞
CVE-2002-2348 Authoria HR Suite AthCGI.EXE 跨站脚本漏洞
CVE-2002-2347 Oracle 9iAS OJSP Demo脚本跨站脚本攻击(XSS)漏洞
CVE-2002-2346 PHPBB2 Avatar图像信息泄露漏洞
CVE-2002-2345 Oracle9iAS Web Cache管理接口明文密码漏洞
CVE-2002-2344 Ensim Webppliance 未授权邮件访问漏洞
CVE-2002-2343 NOCC Webmail脚本注入漏洞
CVE-2002-2342 Bannermatic World Readable数据文件信息泄露漏洞

Showing top 20 of 55 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2007-5690

No comments yet


Leave a comment