PT-2012-4459 · Cisco · Cisco Webex Recording Format (Wrf) Player
Published
2012-06-29
·
Updated
2018-12-03
·
CVE-2012-3055
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco WebEx Recording Format (WRF) player versions T27 L through SP11 EP26
Cisco WebEx Recording Format (WRF) player versions T27 LB through SP21 EP10
Cisco WebEx Recording Format (WRF) player versions T27 LC through SP25 EP10
Cisco WebEx Recording Format (WRF) player versions T27 LD through SP32 CP1
Cisco WebEx Recording Format (WRF) player versions T28 L10N through SP0 EP9
Description
A stack-based buffer overflow issue allows remote attackers to execute arbitrary code via a crafted DHT chunk in a JPEG image within a WRF file.
Recommendations
For versions T27 L through SP11 EP26, update to a version after SP11 EP26 to resolve the issue.
For versions T27 LB through SP21 EP10, update to a version after SP21 EP10 to resolve the issue.
For versions T27 LC through SP25 EP10, update to a version after SP25 EP10 to resolve the issue.
For versions T27 LD through SP32 CP1, update to a version after SP32 CP1 to resolve the issue.
For versions T28 L10N through SP0 EP9, update to a version after SP0 EP9 to resolve the issue.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Webex Recording Format (Wrf) Player