| PROBLEM: | A buffer overflow vulnerability exists in an ActiveX control used by the WebEx Meeting manager. Exploitation of this vulnerability could allow a remote attacker to execute arbitrary code on the user client machine. |
| PLATFORM: | WebEx Meeting Manager |
| DAMAGE: | Execute arbitrary code |
| SOLUTION: | Upgrade to the appropriate version. |
| VULNERABILITY ASSESSMENT: |
The risk is MEDIUM. Exploitation of this vulnerability could allow a remote attacker to execute arbitrary code on the user client machine. |
| CVSS 2 BASE SCORE: TEMPORAL SCORE: VECTOR: |
7.5 6.2 (AV:N/AC:L/Au:N/C:P/I:P/A:P/E:F/RL:OF/RC:C) |
| LINKS: | |
| CIAC BULLETIN: | http://www.ciac.org/ciac/bulletins/s-359.shtml |
| ORIGINAL BULLETIN: | http://www.cisco.com/en/US/products/products_security_advisory09186a00809e2006.shtml |
| CVE: | CVE-2008-2737 |
REVISION HISTORY:
09/10/2008 - revised S-359 to reflect changed Cisco made in Cisco Security Advisory
Document ID: 107751 where they updated the Software Fixes section and
updated to the software naming scheme.
[***** Start Cisco Security Advisory Document ID: 107751 *****]
Summary
Affected Products
Details
Vulnerability Scoring Details
Impact
Software Versions and Fixes
Workarounds
Obtaining Fixed Software
Exploitation and Public Announcements
Status of this Notice: FINAL
Distribution
Revision History
Cisco Security Procedures
A buffer overflow vulnerability exists in an ActiveX control used by the WebEx Meeting Manager. Exploitation of this vulnerability could allow a remote attacker to execute arbitrary code on the user client machine. The WebEx Meeting Manager is a client-side program that is provided by the Cisco WebEx meeting service. The Cisco WebEx meeting service automatically downloads, installs, and configures Meeting Manager the first time a user begins or joins a meeting.
When users connect to the WebEx meeting service, the WebEx Meeting Manager is automatically upgraded to the latest version. There is a manual workaround available for users who are not able to connect to the WebEx meeting service.
Cisco WebEx is in the process of upgrading the meeting service infrastructure with fixed versions of the affected file.
This advisory is posted at http://www.cisco.com/warp/public/707/cisco-sa-20080814-webex.shtml.
[Expand all sections] [Collapse all sections]
Affected Products
Details
Vulnerability Scoring Details
Impact
Software Versions and Fixes
Workarounds
Obtaining Fixed Software
Exploitation and Public Announcements
Status of this Notice: FINAL
Distribution
Revision History
[***** End Cisco Security Advisory Document ID: 107751 *****]
Voice: +1 866-941-2472 (7 x 24)
E-mail: doecirc@doecirc.energy.gov
World Wide Web: http://www.doecirc.energy.gov/