First published: Thu May 08 2014(Updated: )
Heap-based buffer overflow in Cisco WebEx Recording Format (WRF) player T27 LD before SP32 EP16, T28 before T28.12, and T29 before T29.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted audio channel in a .wrf file, aka Bug ID CSCuc39458.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco WebEx WRF Player | =t27ld | |
Cisco WebEx WRF Player | =t28 | |
Cisco WebEx WRF Player | =t29 | |
Cisco WebEx Advanced Recording Format Player | =t27ld | |
Cisco WebEx Advanced Recording Format Player | =t28 | |
Cisco WebEx Advanced Recording Format Player | =t29 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2134 is rated as a high severity vulnerability due to its potential to allow remote code execution and denial of service.
To mitigate CVE-2014-2134, users should upgrade to the latest version of Cisco WebEx Recording Format Player that is not affected by this vulnerability.
CVE-2014-2134 affects Cisco WebEx Recording Format Player versions T27 LD before SP32 EP16, T28 before T28.12, and T29 before T29.2.
CVE-2014-2134 can enable remote attackers to execute arbitrary code or cause a denial of service through crafted audio channels in .wrf files.
Yes, CVE-2014-2134 specifically affects the processing of .wrf files in the Cisco WebEx Recording Format Player.