CERT-In Vulnerability Note
CIVN-2009-0157
Multiple Cisco WebEx WRF Player Vulnerabilities
Original Issue Date:December 30, 2009
Severity Rating: HIGH
Systems Affected
Overview
Multiple buffer overflow vulnerabilities have been reported in the Cisco WebEx Recording Format WRF Player. A remote attacker can execute arbitrary code on a targeted in some occasions.
Description
The WebEx meeting service is a hosted multimedia conferencing solution from Cisco. The WebEx Recording Format WRF is a file format that is used to store WebEx meeting recordings that have been recorded on the computer of an on-line meeting attendee. The WRF Player is an application that is used to play back and edit WRF files files with .wrf extensions .
Multiple buffer overflow vulnerabilities exist in the WRF Player. The vulnerabilities may lead to a crash of the WRF Player application, or in some cases, lead to remote code execution. The vulnerability is due to buffer overflow errors when processing malformed ".wrf" WebEx Recording Format files. A remote user could exploit this vulnerability by convincing a targeted user to open a maliciously crafted WRF file. If the user opens the file using the WRF Player, the attacker could execute arbitrary code with the privileges of the targeted user.
Solution
Apply appropriate patch as mentioned in
Cisco Security Advisory
Vendor Information
CISCO
http://www.cisco.com/en/US/products/products_security_advisory09186a0080b0a577.shtml
References
CISCO
http://tools.cisco.com/security/center/viewAlert.x?alertId=19499
VUPEN
http://www.vupen.com/english/advisories/2009/3574
SecurityTracker
http://securitytracker.com/alerts/2009/Dec/1023360.html
CVE Name
CVE-2009-2875
CVE-2009-2876
CVE-2009-2877
CVE-2009-2878
CVE-2009-2879
CVE-2009-2880
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-2436857
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|