Cisco WebEx WRF and ATAS32 File Format Multiple Remote Buffer Overflow Vulnerabilities
BID:50373
Info
Cisco WebEx WRF and ATAS32 File Format Multiple Remote Buffer Overflow Vulnerabilities
| Bugtraq ID: | 50373 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2011-3319 CVE-2011-4004 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 26 2011 12:00AM |
| Updated: | Dec 07 2011 10:17PM |
| Credit: | TippingPoint |
| Vulnerable: |
Cisco WebEx (Windows) 27.10 Cisco WebEx (Windows) 26.49.32 Cisco WebEx (Windows) 27LC SP22 Cisco WebEx (Windows) 27LB SP21 EP3 Cisco WebEx (Windows) 27.00 Cisco WebEx (Windows) 26.00 Cisco WebEx (Mac OS X) 27.11.8 Cisco WebEx (Mac OS X) 26.49.35 Cisco WebEx (Mac OS X) 27LC SP22 Cisco WebEx (Mac OS X) 27LB SP21 EP3 Cisco WebEx (Mac OS X) 27.00 Cisco WebEx (Mac OS X) 26.00 Cisco WebEx (Linux) 27.11.8 Cisco WebEx (Linux) 26.49.35 Cisco WebEx (Linux) 27LC SP22 Cisco WebEx (Linux) 27LB SP21 EP3 Cisco WebEx (Linux) 27.00 Cisco WebEx (Linux) 26.00 Cisco WebEx 27 Cisco WebEx 0 |
| Not Vulnerable: |
Cisco WebEx (Windows) T27 SP28 Cisco WebEx (Windows) T27 SP25 EP3 Cisco WebEx (Windows) T27 SP23 Cisco WebEx (Windows) T27 SP21 EP9 Cisco WebEx (Windows) T27 SP11 EP23 Cisco WebEx (Windows) T27 FR20 Cisco WebEx (Windows) T26 SP49 EP40 Cisco WebEx (Mac OS X) T27 SP28 Cisco WebEx (Mac OS X) T27 SP25 EP3 Cisco WebEx (Mac OS X) T27 SP23 Cisco WebEx (Mac OS X) T27 SP21 EP9 Cisco WebEx (Mac OS X) T27 SP11 EP23 Cisco WebEx (Mac OS X) T27 FR20 Cisco WebEx (Mac OS X) T26 SP49 EP40 Cisco WebEx (Linux) T27 SP28 Cisco WebEx (Linux) T27 SP25 EP3 Cisco WebEx (Linux) T27 SP23 Cisco WebEx (Linux) T27 SP21 EP9 Cisco WebEx (Linux) T27 SP11 EP23 Cisco WebEx (Linux) T27 FR20 Cisco WebEx (Linux) T26 SP49 EP40 |
Discussion
Cisco WebEx WRF and ATAS32 File Format Multiple Remote Buffer Overflow Vulnerabilities
Cisco WebEx is prone to multiple remote buffer-overflow vulnerabilities.
An attacker can exploit these issues to execute arbitrary code with the privileges of the affected application. Failed exploit attempts may result in a denial-of-service condition.
Cisco WebEx is prone to multiple remote buffer-overflow vulnerabilities.
An attacker can exploit these issues to execute arbitrary code with the privileges of the affected application. Failed exploit attempts may result in a denial-of-service condition.
Exploit / POC
Cisco WebEx WRF and ATAS32 File Format Multiple Remote Buffer Overflow Vulnerabilities
The vendor reports exploit code exists for these issues.
The vendor reports exploit code exists for these issues.
Solution / Fix
Cisco WebEx WRF and ATAS32 File Format Multiple Remote Buffer Overflow Vulnerabilities
Solution:
Vendor updates are available. Please see the referenced vendor advisory for more information.
Solution:
Vendor updates are available. Please see the referenced vendor advisory for more information.
References
Cisco WebEx WRF and ATAS32 File Format Multiple Remote Buffer Overflow Vulnerabilities
References:
References:
- WebEx Homepage (Cisco)
- Buffer Overflow Vulnerabilities in the Cisco WebEx Player (Cisco)
- ZDI-11-308 Cisco WebEx Player ATAS32.DLL linesProcessed Remote Code Execution Vu (Zero Day Initiative)
- ZDI-11-341 Cisco WebEx Player WRF Type 0 Parsing Remote Code Execution Vulnerabi (Zero Day Initiative)