Cisco WebEx WRF and ARF File Format Multiple Remote Buffer Overflow Vulnerabilities
BID:54213
Info
Cisco WebEx WRF and ARF File Format Multiple Remote Buffer Overflow Vulnerabilities
| Bugtraq ID: | 54213 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2012-3053 CVE-2012-3054 CVE-2012-3055 CVE-2012-3056 CVE-2012-3057 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 27 2012 12:00AM |
| Updated: | Mar 19 2015 09:40AM |
| Credit: | iDefense and Microsoft Vulnerability Research (MSVR) |
| Vulnerable: |
Cisco WebEx (Windows) 27.10 Cisco WebEx (Windows) 26.49.32 Cisco WebEx (Windows) T27 SP28 Cisco WebEx (Windows) T27 SP25 EP3 Cisco WebEx (Windows) T27 SP23 Cisco WebEx (Windows) T27 SP21 EP9 Cisco WebEx (Windows) T27 SP11 EP23 Cisco WebEx (Windows) T27 LD SP32 CP1 Cisco WebEx (Windows) T27 LD SP32 Cisco WebEx (Windows) T27 LC SP25 EP9 Cisco WebEx (Windows) T27 LC SP25 EP10 Cisco WebEx (Windows) T27 LB SP21 EP10 Cisco WebEx (Windows) T27 L SP11 EP26 Cisco WebEx (Windows) T27 FR20 Cisco WebEx (Windows) T26 SP49 EP40 Cisco WebEx (Windows) 27LC SP22 Cisco WebEx (Windows) 27LB SP21 EP3 Cisco WebEx (Windows) 27.00 Cisco WebEx (Windows) 26.00 Cisco WebEx (Mac OS X) 27.11.8 Cisco WebEx (Mac OS X) 26.49.35 Cisco WebEx (Mac OS X) T27 SP28 Cisco WebEx (Mac OS X) T27 SP25 EP3 Cisco WebEx (Mac OS X) T27 SP23 Cisco WebEx (Mac OS X) T27 SP21 EP9 Cisco WebEx (Mac OS X) T27 SP11 EP23 Cisco WebEx (Mac OS X) T27 LD SP32 CP1 Cisco WebEx (Mac OS X) T27 LD SP32 Cisco WebEx (Mac OS X) T27 LC SP25 EP9 Cisco WebEx (Mac OS X) T27 LC SP25 EP10 Cisco WebEx (Mac OS X) T27 LB SP21 EP10 Cisco WebEx (Mac OS X) T27 L SP11 EP26 Cisco WebEx (Mac OS X) T27 FR20 Cisco WebEx (Mac OS X) T26 SP49 EP40 Cisco WebEx (Mac OS X) 27LC SP22 Cisco WebEx (Mac OS X) 27LB SP21 EP3 Cisco WebEx (Mac OS X) 27.00 Cisco WebEx (Mac OS X) 26.00 Cisco WebEx (Ma T27 LD SP32 Cisco WebEx (Linux) 27.11.8 Cisco WebEx (Linux) 26.49.35 Cisco WebEx (Linux) T27 SP28 Cisco WebEx (Linux) T27 SP25 EP3 Cisco WebEx (Linux) T27 SP23 Cisco WebEx (Linux) T27 SP21 EP9 Cisco WebEx (Linux) T27 SP11 EP23 Cisco WebEx (Linux) T27 LD SP32 CP1 Cisco WebEx (Linux) T27 LD SP32 Cisco WebEx (Linux) T27 LC SP25 EP9 Cisco WebEx (Linux) T27 LC SP25 EP10 Cisco WebEx (Linux) T27 LB SP21 EP10 Cisco WebEx (Linux) T27 L SP11 EP26 Cisco WebEx (Linux) T27 FR20 Cisco WebEx (Linux) T26 SP49 EP40 Cisco WebEx (Linux) 27LC SP22 Cisco WebEx (Linux) 27LB SP21 EP3 Cisco WebEx (Linux) 27.00 Cisco WebEx (Linux) 26.00 Cisco WebEx 28 Cisco WebEx 27 Cisco WebEx 0 |
| Not Vulnerable: | |
Discussion
Cisco WebEx WRF and ARF File Format Multiple Remote Buffer Overflow Vulnerabilities
Cisco WebEx is prone to multiple remote buffer-overflow vulnerabilities because it fails to perform adequate boundary-checks on user-supplied data.
An attacker can exploit these issues to execute arbitrary code with the privileges of the affected application. Failed exploit attempts will result in a denial-of-service condition.
Cisco WebEx is prone to multiple remote buffer-overflow vulnerabilities because it fails to perform adequate boundary-checks on user-supplied data.
An attacker can exploit these issues to execute arbitrary code with the privileges of the affected application. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
Cisco WebEx WRF and ARF File Format Multiple Remote Buffer Overflow Vulnerabilities
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Cisco WebEx WRF and ARF File Format Multiple Remote Buffer Overflow Vulnerabilities
Solution:
Vendor updates are available. Please see the referenced vendor advisory for more information.
Solution:
Vendor updates are available. Please see the referenced vendor advisory for more information.
References
Cisco WebEx WRF and ARF File Format Multiple Remote Buffer Overflow Vulnerabilities
References:
References: