Release DateDec 31, 2011 |
Severityhigh |
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems. |
DescriptionThis indicates an attack attempt against a Heap Memory Corruption vulnerability in Cisco WebEx Player.The vulnerability is caused due to insufficient validation of some values in WebEx Recording Format (WRF) files. A remote attacker can exploit this by sending a specially crafted WRF file. Successful exploitation may allow the attacker to execute arbitrary code on the target host in the context of the application. |
Affected ProductsCisco Systems WebEx Player Prior to T26 SP49 EP40Cisco Systems WebEx Player Prior to T27 FR20 Cisco Systems WebEx Player Prior to T27 SP11 EP23 Cisco Systems WebEx Player Prior to T27 SP21 EP9 Cisco Systems WebEx Player Prior to T27 SP23 Cisco Systems WebEx Player Prior to T27 SP25 EP3 Cisco Systems WebEx Player Prior to T27 SP28 |
Recommended ActionsApply patches or fixes, available from the website:http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-webex |
Coverage IPS
VCM |
Common Vulnerabilities and Exposures (CVE)CVE-2011-3319 |
Reference/shttps://portal.telussecuritylabs.com/threat/TSL20111205-06 |