cisco-sa-20180905-webex-player-dos: Cisco Webex Player WRF Files Denial of Service Vulnerability
A vulnerability in the Cisco Webex Player for Webex Recording Format (WRF) files could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. An attacker could exploit this vulnerability by sending a user a link or email attachment with a malicious WRF file and persuading the user to open the file in the Cisco Webex Player. A successful exploit could cause the affected player to crash, resulting in a DoS condition. For more information about this vulnerability, see the Details section of this security advisory.
There are no workarounds that address this vulnerability.
This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180905-webex-player-dos
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-20180905-webex-player-dos?
The severity of cisco-sa-20180905-webex-player-dos is classified as high due to its potential to cause a denial of service.
How do I fix cisco-sa-20180905-webex-player-dos?
To fix cisco-sa-20180905-webex-player-dos, update the Cisco Webex Player to the latest version recommended by Cisco.
What types of attacks can exploit cisco-sa-20180905-webex-player-dos?
An unauthenticated remote attacker can exploit cisco-sa-20180905-webex-player-dos by sending a malicious link or email attachment.
What versions of Cisco Webex Player are affected by cisco-sa-20180905-webex-player-dos?
cisco-sa-20180905-webex-player-dos affects all versions of the Cisco Webex Player that are vulnerable, as specified in Cisco advisories.
Is user interaction required to exploit cisco-sa-20180905-webex-player-dos?
Yes, user interaction is required, as the attacker must send a malicious WRF file link or email attachment to the victim.