Lucene search

K
ciscoCiscoCISCO-SA-20140710-CVE-2014-3311
HistoryJul 10, 2014 - 3:27 p.m.

Cisco WebEx Meetings Client Heap-Based Buffer Overflow Vulnerability

2014-07-1015:27:10
tools.cisco.com
17

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

EPSS

0.031

Percentile

91.1%

A vulnerability in the file sharing functionality of the Cisco WebEx Meetings client could allow an
unauthenticated, remote attacker to trigger a heap-based buffer overflow
in the Cisco WebEx Meetings client running
on another user’s computer.

The
vulnerability exists because the affected software does not properly check the bounds of the data being
transferred. An attacker could exploit this vulnerability by using a
modified Cisco WebEx Meetings client. An exploit could allow the attacker to execute code on the remote computer or
cause a denial of service (DoS) condition by crashing the remote Cisco WebEx Meetings client.

Cisco has confirmed the vulnerability in a security notice and released software updates.

To exploit this vulnerability, an attacker may attempt to convince a targeted user to download a malformed file with the Cisco WebEx Meetings client by using misleading language and instructions.

Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.

Affected configurations

Vulners
Node
ciscowebex_meeting_centerMatchany
OR
ciscowebex_meetings_serverMatchany
OR
ciscowebex_meeting_centerMatchany
OR
ciscowebex_meetings_serverMatchany
VendorProductVersionCPE
ciscowebex_meeting_centeranycpe:2.3:a:cisco:webex_meeting_center:any:*:*:*:*:*:*:*
ciscowebex_meetings_serveranycpe:2.3:a:cisco:webex_meetings_server:any:*:*:*:*:*:*:*

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

EPSS

0.031

Percentile

91.1%

Related for CISCO-SA-20140710-CVE-2014-3311