安全研究

安全漏洞
Cisco WebEx WRF文件格式多个远程内存破坏漏洞

发布日期:2012-10-10
更新日期:2012-10-11

受影响系统:
Cisco WebEx  (Windows) T27 LD SP32 CP1
Cisco WebEx  (Windows) T27 LD SP32
Cisco WebEx  (Windows) T27 LC SP25 EP9
Cisco WebEx  (Windows) T27 LC SP25 EP10
Cisco WebEx  (Windows) T27 LB SP21 EP10
Cisco WebEx  (Windows) T27 L SP11 EP26
Cisco WebEx  (Windows) T27 FR20
Cisco WebEx  (Windows) 27.10
Cisco WebEx  (Windows) 27.00
Cisco WebEx  (Mac OS X) T27 SP28
Cisco WebEx  (Mac OS X) T27 SP25 EP3
Cisco WebEx  (Mac OS X) T27 SP23
Cisco WebEx  (Mac OS X) T27 SP21 EP9
Cisco WebEx  (Mac OS X) T27 SP11 EP23
Cisco WebEx  (Mac OS X) T27 LD SP32 CP1
Cisco WebEx  (Mac OS X) T27 LD SP32
Cisco WebEx  (Mac OS X) T27 LD SP32
Cisco WebEx  (Mac OS X) T27 LC SP25 EP9
Cisco WebEx  (Mac OS X) T27 LC SP25 EP10
Cisco WebEx  (Mac OS X) T27 LB SP21 EP10
Cisco WebEx  (Mac OS X) T27 L SP11 EP26
Cisco WebEx  (Mac OS X) T27 FR20
Cisco WebEx  (Mac OS X) 27.11.8
Cisco WebEx  (Mac OS X) 27.00
Cisco WebEx  (Linux) T27 SP28
Cisco WebEx  (Linux) T27 SP25 EP3
Cisco WebEx  (Linux) T27 SP23
Cisco WebEx  (Linux) T27 SP21 EP9
Cisco WebEx  (Linux) T27 SP11 EP23
Cisco WebEx  (Linux) T27 LD SP32 CP1
Cisco WebEx  (Linux) T27 LD SP32
Cisco WebEx  (Linux) T27 LC SP25 EP9
Cisco WebEx  (Linux) T27 LC SP25 EP10
Cisco WebEx  (Linux) T27 LB SP21 EP10
Cisco WebEx  (Linux) T27 L SP11 EP26
Cisco WebEx  (Linux) T27 FR20
Cisco WebEx  (Linux) 27.11.8
Cisco WebEx  (Linux) 27.11.8
Cisco WebEx  (Linux) 27.00
描述:
BUGTRAQ  ID: 55866
CVE ID: CVE-2012-3936,CVE-2012-3937,CVE-2012-3938,CVE-2012-3939,CVE-2012-3940,CVE-2012-3941

WebEx会议服务是Cisco WebEx管理和维护的托管多媒体会议解决方案。

Cisco WebEx存在多个远程内存破坏漏洞,攻击者可利用这些漏洞在受影响应用内执行任意代码。

<*来源:Beyond Security,
  *>

建议:
厂商补丁:

Cisco
-----
目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载:

http://www.cisco.com/warp/public/707/advisory.html

浏览次数:2476
严重程度:0(网友投票)
本安全漏洞由绿盟科技翻译整理,版权所有,未经许可,不得转载
绿盟科技给您安全的保障