Vulnerability Description
Stack-based buffer overflow in Cisco WebEx Meeting Center T27LB before SP21 EP3 and T27LC before SP22 allows user-assisted remote authenticated users to execute arbitrary code by providing a crafted .atp file and then disconnecting from a meeting. NOTE: since this is a site-specific issue with no expected action for consumers, it might be REJECTed.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Webex Meeting Center | 27.0 |
Related Weaknesses (CWE)
References
- http://securitytracker.com/id?1025015
- http://tools.cisco.com/security/center/viewAlert.x?alertId=22355
- http://www.coresecurity.com/content/webex-atp-and-wrf-overflow-vulnerabilities
- http://www.securityfocus.com/archive/1/516095/100/0/threaded
- http://www.securityfocus.com/bid/46078
- http://www.vupen.com/english/advisories/2011/0260Vendor Advisory
- http://securitytracker.com/id?1025015
- http://tools.cisco.com/security/center/viewAlert.x?alertId=22355
- http://www.coresecurity.com/content/webex-atp-and-wrf-overflow-vulnerabilities
- http://www.securityfocus.com/archive/1/516095/100/0/threaded
- http://www.securityfocus.com/bid/46078
- http://www.vupen.com/english/advisories/2011/0260Vendor Advisory
FAQ
What is CVE-2010-3270?
CVE-2010-3270 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Stack-based buffer overflow in Cisco WebEx Meeting Center T27LB before SP21 EP3 and T27LC before SP22 allows user-assisted remote authenticated users to execute arbitrary code by providing a crafted ....
How severe is CVE-2010-3270?
CVE-2010-3270 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-3270?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Webex Meeting Center.