First published: Fri Jun 29 2012(Updated: )
Heap-based buffer overflow in the Cisco WebEx Recording Format (WRF) player T27 L through SP11 EP26, T27 LB through SP21 EP10, T27 LC before SP25 EP11, T27 LD before SP32 CP2, and T28 L10N before SP1 allows remote attackers to execute arbitrary code via a crafted WRF file, aka Bug ID CSCtz72977.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco WebEx Advanced Recording Format Player | >=27.11.0<=27.11.26 | |
Cisco WebEx Advanced Recording Format Player | >=27.21.0<=27.21.10 | |
Cisco WebEx Advanced Recording Format Player | >=27.25.0<27.25.11 | |
Cisco WebEx Advanced Recording Format Player | >=27.32.0<27.32.2 | |
Cisco WebEx Advanced Recording Format Player | >=28.0.0<28.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-3054 is rated as high severity due to the potential for remote code execution.
To fix CVE-2012-3054, update the Cisco WebEx Recording Format Player to a version that is not vulnerable.
CVE-2012-3054 affects multiple versions of the Cisco WebEx Recording Format Player including T27 and T28 series before specified service packs.
Yes, CVE-2012-3054 can be exploited remotely through a crafted WRF file.
CVE-2012-3054 is a heap-based buffer overflow vulnerability.