PT-2012-4459 · Cisco · Cisco Webex Recording Format (Wrf) Player

Publicado

2012-06-29

·

Atualizado

2018-12-03

·

CVE-2012-3055

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco WebEx Recording Format (WRF) player versions T27 L through SP11 EP26 Cisco WebEx Recording Format (WRF) player versions T27 LB through SP21 EP10 Cisco WebEx Recording Format (WRF) player versions T27 LC through SP25 EP10 Cisco WebEx Recording Format (WRF) player versions T27 LD through SP32 CP1 Cisco WebEx Recording Format (WRF) player versions T28 L10N through SP0 EP9
Description A stack-based buffer overflow issue allows remote attackers to execute arbitrary code via a crafted DHT chunk in a JPEG image within a WRF file.
Recommendations For versions T27 L through SP11 EP26, update to a version after SP11 EP26 to resolve the issue. For versions T27 LB through SP21 EP10, update to a version after SP21 EP10 to resolve the issue. For versions T27 LC through SP25 EP10, update to a version after SP25 EP10 to resolve the issue. For versions T27 LD through SP32 CP1, update to a version after SP32 CP1 to resolve the issue. For versions T28 L10N through SP0 EP9, update to a version after SP0 EP9 to resolve the issue.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-3055

Produtos afetados

Cisco Webex Recording Format (Wrf) Player