First published: Fri Dec 18 2009(Updated: )
Stack-based buffer overflow in ataudio.dll in the Cisco WebEx WRF Player 26.x before 26.49.32 for Windows, 27.x before 27.10.x (aka T27SP10) for Windows, 26.x before 26.49.35 for Mac OS X and Linux, and 27.x before 27.11.8 for Mac OS X and Linux allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted WebEx Recording Format (WRF) file.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Webex | =26.00 | |
Webex | =27.00 | |
Webex | =27.00 | |
Webex | =26.00 | |
Webex | =26.00 | |
Webex | =27.00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2877 has a severity rating of medium, primarily due to its potential to cause denial of service.
To mitigate CVE-2009-2877, users should upgrade to the patched versions of Cisco WebEx which address this vulnerability.
CVE-2009-2877 affects Cisco WebEx versions 26.x before 26.49.32 and 27.x before 27.10.x for Windows, and similar versions for Mac OS X and Linux.
CVE-2009-2877 is classified as a stack-based buffer overflow vulnerability.
Yes, CVE-2009-2877 can be exploited remotely by attackers to cause a denial of service.