Vulnerability Description
Stack-based buffer overflow in ataudio.dll in the Cisco WebEx WRF Player 26.x before 26.49.32 for Windows, 27.x before 27.10.x (aka T27SP10) for Windows, 26.x before 26.49.35 for Mac OS X and Linux, and 27.x before 27.11.8 for Mac OS X and Linux allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted WebEx Recording Format (WRF) file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Webex | 26.00 |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/37810Vendor Advisory
- http://securitytracker.com/id?1023360
- http://tools.cisco.com/security/center/viewAlert.x?alertId=19499PatchVendor Advisory
- http://tools.cisco.com/security/center/viewIpsSignature.x?signatureId=22660&signPatchVendor Advisory
- http://tools.cisco.com/security/center/viewIpsSignature.x?signatureId=22661&signPatchVendor Advisory
- http://tools.cisco.com/security/center/viewIpsSignature.x?signatureId=22662&signPatchVendor Advisory
- http://tools.cisco.com/security/center/viewIpsSignature.x?signatureId=22663&signPatchVendor Advisory
- http://tools.cisco.com/security/center/viewIpsSignature.x?signatureId=22799&signPatchVendor Advisory
- http://tools.cisco.com/security/center/viewIpsSignature.x?signatureId=23040&signPatchVendor Advisory
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080b0a577.sPatchVendor Advisory
- http://www.fortiguard.com/advisory/FGA-2009-48.html
- http://www.fortiguard.com/encyclopedia/vulnerability/cisco.webex.player.ataudio.
- http://www.osvdb.org/61127
- http://www.securityfocus.com/bid/37352PatchVendor Advisory
- http://www.vupen.com/english/advisories/2009/3574PatchVendor Advisory
FAQ
What is CVE-2009-2877?
CVE-2009-2877 is a vulnerability with a CVSS score of 9.3 (HIGH). Stack-based buffer overflow in ataudio.dll in the Cisco WebEx WRF Player 26.x before 26.49.32 for Windows, 27.x before 27.10.x (aka T27SP10) for Windows, 26.x before 26.49.35 for Mac OS X and Linux, a...
How severe is CVE-2009-2877?
CVE-2009-2877 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-2877?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Webex.