First published: Thu Oct 27 2011(Updated: )
Buffer overflow in the ATAS32 processing functionality in the Cisco WebEx Recording Format (WRF) player T26 before SP49 EP40 and T27 before SP28 allows remote attackers to execute arbitrary code via a crafted WRF file.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco WebEx Advanced Recording Format Player | =27.10 | |
Cisco WebEx Advanced Recording Format Player | =27.13 | |
Cisco WebEx Advanced Recording Format Player | =27 | |
Cisco WebEx Advanced Recording Format Player | =27.12 | |
Cisco WebEx Advanced Recording Format Player | =26 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4004 has been classified with high severity due to its potential to allow remote code execution.
To fix CVE-2011-4004, users should update to Cisco WebEx recording format player version 27.14 or later.
CVE-2011-4004 enables attackers to execute arbitrary code through specially crafted WRF files.
Versions 26 and 27.x of the Cisco WebEx Recording Format Player prior to specific patches are affected by CVE-2011-4004.
Yes, CVE-2011-4004 can be exploited remotely by sending a malicious WRF file to the victim.