|Date: (C)2007-10-29 (M)2017-07-31|| |
** DISPUTED ** Buffer overflow in sethdlc.c in the Asterisk Zaptel 126.96.36.199 might allow local users to gain privileges via a long device name (interface name) in the ifr_name field. NOTE: the vendor disputes this issue, stating that the application requires root access, so privilege boundaries are not crossed.
|CVSS Score: 4.6||Access Vector: LOCAL|
|Exploit Score: 3.9||Access Complexity: LOW|
|Impact Score: 6.4||Authentication: NONE|
| ||Confidentiality: PARTIAL|
| ||Integrity: PARTIAL|
| ||Availability: PARTIAL|