Cisco WebEx ARF Player LZW Decompress Memory Corruption Vulnerability
BID:67261
Info
Cisco WebEx ARF Player LZW Decompress Memory Corruption Vulnerability
| Bugtraq ID: | 67261 |
| Class: | Design Error |
| CVE: |
CVE-2014-2133 |
| Remote: | Yes |
| Local: | No |
| Published: | May 07 2014 12:00AM |
| Updated: | May 07 2014 12:00AM |
| Credit: | Fortinet |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Cisco WebEx ARF Player LZW Decompress Memory Corruption Vulnerability
Cisco WebEx ARF Player is prone to a remote memory-corruption vulnerability.
An attacker could exploit this issue to crash the affected player causing denial-of-service conditions or execute arbitrary code in context of the user.
This issue is being tracked by Cisco Bug ID CSCuj87565.
Cisco WebEx ARF Player is prone to a remote memory-corruption vulnerability.
An attacker could exploit this issue to crash the affected player causing denial-of-service conditions or execute arbitrary code in context of the user.
This issue is being tracked by Cisco Bug ID CSCuj87565.
Exploit / POC
Cisco WebEx ARF Player LZW Decompress Memory Corruption Vulnerability
Attackers can use standard, readily available tools to exploit this issue.
Attackers can use standard, readily available tools to exploit this issue.
Solution / Fix
Cisco WebEx ARF Player LZW Decompress Memory Corruption Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Cisco WebEx ARF Player LZW Decompress Memory Corruption Vulnerability
References:
References: