CVE-2014-2135: Buffer Overflow
Buffer overflow in Cisco Advanced Recording Format (ARF) player T27 LD before SP32 EP16, T28 before T28.12, and T29 before T29.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted .arf file, aka Bug IDs CSCul87216 and CSCuj07603.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2135?
CVE-2014-2135 has a high severity due to the potential for remote code execution and denial of service.
How do I fix CVE-2014-2135?
To fix CVE-2014-2135, update to the latest fixed version of Cisco WebEx Advanced Recording Format Player.
Which versions are affected by CVE-2014-2135?
CVE-2014-2135 affects Cisco WebEx Advanced Recording Format Player versions T27 LD before SP32 EP16, T28 before T28.12, and T29 before T29.2.
What types of attacks are possible through CVE-2014-2135?
CVE-2014-2135 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted .arf file.
Is there a workaround for CVE-2014-2135?
There are no known workarounds for CVE-2014-2135; updating the software is the recommended action.