PT-2012-4459 · Cisco · Cisco Webex Recording Format (Wrf) Player
Publicado
2012-06-29
·
Atualizado
2018-12-03
·
CVE-2012-3055
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco WebEx Recording Format (WRF) player versions T27 L through SP11 EP26
Cisco WebEx Recording Format (WRF) player versions T27 LB through SP21 EP10
Cisco WebEx Recording Format (WRF) player versions T27 LC through SP25 EP10
Cisco WebEx Recording Format (WRF) player versions T27 LD through SP32 CP1
Cisco WebEx Recording Format (WRF) player versions T28 L10N through SP0 EP9
Description
A stack-based buffer overflow issue allows remote attackers to execute arbitrary code via a crafted DHT chunk in a JPEG image within a WRF file.
Recommendations
For versions T27 L through SP11 EP26, update to a version after SP11 EP26 to resolve the issue.
For versions T27 LB through SP21 EP10, update to a version after SP21 EP10 to resolve the issue.
For versions T27 LC through SP25 EP10, update to a version after SP25 EP10 to resolve the issue.
For versions T27 LD through SP32 CP1, update to a version after SP32 CP1 to resolve the issue.
For versions T28 L10N through SP0 EP9, update to a version after SP0 EP9 to resolve the issue.
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Webex Recording Format (Wrf) Player