CVE-2013-1116: Buffer Overflow
Buffer overflow in Cisco WebEx Advanced Recording Format (ARF) player T27 LD before SP32 EP16, T27 L10N before SP32ORION111, and T28 before T28.8 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted ARF file, aka Bug IDs CSCue74147 and CSCub28383.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1116?
CVE-2013-1116 has a high severity rating due to its potential for remote code execution and denial of service.
How do I fix CVE-2013-1116?
The recommended fix for CVE-2013-1116 is to upgrade to the latest version of the Cisco WebEx Advanced Recording Format Player.
Which versions of the Cisco WebEx ARF player are affected by CVE-2013-1116?
Versions T27 LD before SP32 EP16, T27 L10N before SP32_ORION111, and T28 before T28.8 are affected by CVE-2013-1116.
Can CVE-2013-1116 lead to data theft?
Yes, CVE-2013-1116 can lead to arbitrary code execution, which may enable data theft depending on the attacker's intent.
Is there a workaround for CVE-2013-1116?
There are no official workarounds for CVE-2013-1116; upgrading to a secure version is the only recommended action.