Dec 16,2009

Cisco WebEx WRF Player Vulnerabilities, (Wed, Dec 16th)

Cisco today released details of a set of buffer overflow vulnerabilities and fixes for their WebEx WRF player. The exploits describe multiple buffer overflows caused by a maliciously crafted WRF file (generally posted on a website), or by attending a WebEx meeting with an attacker attending. The results of the exploit can result in execution of arbitrary code on the target system. The exploits are categorized as: CVE-2009-2875, CVE-2009-2876, CVE-2009-2877, CVE-2009-2878, CVE-2009-2879 and CVE-2009-2880. The WebEx site itself has the fixed client code. If you have an inhouse WebEx server, updating the server updates all the clients (as they connect). You ...

Filed Under: SANS Internet Storm Center, Tags: ,

Leave a Reply