PT-2012-4459 · Cisco · Cisco Webex Recording Format (Wrf) Player

Published

2012-06-29

·

Updated

2018-12-03

·

CVE-2012-3055

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco WebEx Recording Format (WRF) player versions T27 L through SP11 EP26 Cisco WebEx Recording Format (WRF) player versions T27 LB through SP21 EP10 Cisco WebEx Recording Format (WRF) player versions T27 LC through SP25 EP10 Cisco WebEx Recording Format (WRF) player versions T27 LD through SP32 CP1 Cisco WebEx Recording Format (WRF) player versions T28 L10N through SP0 EP9
Description A stack-based buffer overflow issue allows remote attackers to execute arbitrary code via a crafted DHT chunk in a JPEG image within a WRF file.
Recommendations For versions T27 L through SP11 EP26, update to a version after SP11 EP26 to resolve the issue. For versions T27 LB through SP21 EP10, update to a version after SP21 EP10 to resolve the issue. For versions T27 LC through SP25 EP10, update to a version after SP25 EP10 to resolve the issue. For versions T27 LD through SP32 CP1, update to a version after SP32 CP1 to resolve the issue. For versions T28 L10N through SP0 EP9, update to a version after SP0 EP9 to resolve the issue.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-3055

Affected Products

Cisco Webex Recording Format (Wrf) Player