Cisco WebEx WRF File Handling Multiple Buffer Overflow Vulnerabilities
BID:37352
Info
Cisco WebEx WRF File Handling Multiple Buffer Overflow Vulnerabilities
| Bugtraq ID: | 37352 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2009-2875 CVE-2009-2876 CVE-2009-2877 CVE-2009-2878 CVE-2009-2879 CVE-2009-2880 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 16 2009 12:00AM |
| Updated: | Dec 23 2009 06:53PM |
| Credit: | Xiaopeng Zhang and Zhenhua Liu of Fortinet's FortiGuard Labs |
| Vulnerable: |
Cisco WebEx (Windows) 27.00 Cisco WebEx (Windows) 26.00 Cisco WebEx (Mac OS X) 27.00 Cisco WebEx (Mac OS X) 26.00 Cisco WebEx (Linux) 27.00 Cisco WebEx (Linux) 26.00 |
| Not Vulnerable: |
Cisco WebEx (Windows) 27.10 Cisco WebEx (Windows) 26.49.32 Cisco WebEx (Mac OS X) 27.11.8 Cisco WebEx (Mac OS X) 26.49.35 Cisco WebEx (Linux) 27.11.8 Cisco WebEx (Linux) 26.49.35 |
Discussion
Cisco WebEx WRF File Handling Multiple Buffer Overflow Vulnerabilities
Cisco WebEx is prone to multiple remote buffer-overflow vulnerabilities because the software fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit these issues to execute arbitrary code with administrative privileges. Successful exploits will completely compromise affected computers. Failed exploit attempts will result in a denial-of-service condition.
Cisco WebEx is prone to multiple remote buffer-overflow vulnerabilities because the software fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit these issues to execute arbitrary code with administrative privileges. Successful exploits will completely compromise affected computers. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
Cisco WebEx WRF File Handling Multiple Buffer Overflow Vulnerabilities
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Cisco WebEx WRF File Handling Multiple Buffer Overflow Vulnerabilities
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Cisco WebEx WRF File Handling Multiple Buffer Overflow Vulnerabilities
References:
References:
- Cisco Security Advisory: Multiple Cisco WebEx WRF Player Vulnerabilities (Cisco)
- WebEx Homepage (Cisco)
- Cisco Security Advisory: Multiple Cisco WebEx WRF Player Vulnerabilities (Cisco Systems Product Security Incident Response Team
)