CVE-2012-3053 Detail
Current Description
Buffer overflow in the Cisco WebEx Advanced Recording Format (ARF) player T27 L through SP11 EP26, T27 LB through SP21 EP10, T27 LC before SP25 EP11, T27 LD before SP32 CP2, and T28 L10N before SP1 allows remote attackers to execute arbitrary code via a crafted ARF file, aka Bug ID CSCtz72985.
Source:
MITRE
View Analysis Description
Analysis Description
Buffer overflow in the Cisco WebEx Advanced Recording Format (ARF) player T27 L through SP11 EP26, T27 LB through SP21 EP10, T27 LC before SP25 EP11, T27 LD before SP32 CP2, and T28 L10N before SP1 allows remote attackers to execute arbitrary code via a crafted ARF file, aka Bug ID CSCtz72985.
Source:
MITRE
Severity
CVSS 3.x Severity and Metrics:
NVD score not yet provided.
CVSS 2.0 Severity and Metrics:
Vector: (AV:N/AC:M/Au:N/C:C/I:C/A:C)
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because
they may have information that would be of interest to you. No inferences should be drawn on account of other sites
being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose.
NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further,
NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about
this page to nvd@nist.gov.
Weakness Enumeration
CWE-ID |
CWE Name |
Source |
CWE-119 |
Improper Restriction of Operations within the Bounds of a Memory Buffer |
NIST
|
Known Affected Software Configurations
Switch to CPE 2.3
Configuration 1 ( hide ) cpe:/a:cisco:webex_advanced_recording_format_player Show Matching CPE(s)
|
From (including) 27.11.0 | Up to (including) 27.11.26 | cpe:/a:cisco:webex_advanced_recording_format_player Show Matching CPE(s)
|
From (including) 27.21.0 | Up to (including) 27.21.10 | cpe:/a:cisco:webex_advanced_recording_format_player Show Matching CPE(s)
|
From (including) 27.25.0 | Up to (excluding) 27.25.11 | cpe:/a:cisco:webex_advanced_recording_format_player Show Matching CPE(s)
|
From (including) 27.32.0 | Up to (excluding) 27.32.2 | cpe:/a:cisco:webex_advanced_recording_format_player Show Matching CPE(s)
|
From (including) 28.0.0 | Up to (excluding) 28.0.1 |
Change History
2 change records found
- show changes
Initial Analysis -
12/3/2018 8:42:32 AM
Action |
Type |
Old Value |
New Value |
Changed |
CPE Configuration |
Record truncated, showing 500 of 564 characters.
View Entire Change Record
OR
*cpe:2.3:a:cisco:webex_advanced_recording_format_player:*:*:*:*:*:*:*:* versions up to (including) 27.11.26
*cpe:2.3:a:cisco:webex_advanced_recording_format_player:*:*:*:*:*:*:*:* versions up to (including) 27.21.10
*cpe:2.3:a:cisco:webex_advanced_recording_format_player:*:*:*:*:*:*:*:* versions up to (including) 27.25.10
*cpe:2.3:a:cisco:webex_advanced_recording_format_player:*:*:*:*:*:*:*:* versions up to (including) 27.32.1
*cpe:2.3:a:cisco:webex_advanced_recording |
Record truncated, showing 500 of 688 characters.
View Entire Change Record
OR
*cpe:2.3:a:cisco:webex_advanced_recording_format_player:*:*:*:*:*:*:*:* versions from (including) 27.11.0 up to (including) 27.11.26
*cpe:2.3:a:cisco:webex_advanced_recording_format_player:*:*:*:*:*:*:*:* versions from (including) 27.21.0 up to (including) 27.21.10
*cpe:2.3:a:cisco:webex_advanced_recording_format_player:*:*:*:*:*:*:*:* versions from (including) 27.25.0 up to (excluding) 27.25.11
*cpe:2.3:a:cisco:webex_advanced_recording_format_player:*:*:*:*:*:*:*:* versio |
Initial CVE Analysis -
7/2/2012 7:47:00 AM
Quick Info
CVE Dictionary Entry:
CVE-2012-3053
NVD Published Date:
06/29/2012
NVD Last Modified:
12/03/2018
|