First published: Wed Feb 02 2011(Updated: )
Multiple buffer overflows in the Cisco WebEx Recording Format (WRF) and Advanced Recording Format (ARF) Players T27LB before SP21 EP3 and T27LC before SP22 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted (1) .wrf or (2) .arf file, related to atas32.dll, a different vulnerability than CVE-2010-3042, CVE-2010-3043, and CVE-2010-3044.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco WebEx Advanced Recording Format Player | =26.49 | |
Cisco WebEx Advanced Recording Format Player | =27.10 | |
Cisco WebEx Advanced Recording Format Player | =27.11.0.3328 | |
Cisco WebEx Advanced Recording Format Player | =27.12 | |
Cisco WebEx Advanced Recording Format Player | =27.13 | |
Cisco WebEx WRF Player | =26.49 | |
Cisco WebEx WRF Player | =27.10 | |
Cisco WebEx WRF Player | =27.11.0.3328 | |
Cisco WebEx WRF Player | =27.12 | |
Cisco WebEx WRF Player | =27.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3041 has a medium severity rating due to its potential for causing application crashes or arbitrary code execution.
To fix CVE-2010-3041, update the affected Cisco WebEx Recording Format Player to at least T27LB SP21 EP3 or T27LC SP22.
CVE-2010-3041 allows remote attackers to execute arbitrary code or cause denial of service by exploiting buffer overflows.
CVE-2010-3041 affects versions T27LB before SP21 EP3 and T27LC before SP22 of the Cisco WebEx Recording Format Players.
The vulnerability CVE-2010-3041 can be triggered by specially crafted .wrf or .arf file formats.