ID

VAR-201309-0032


CVE

CVE-2013-1116


TITLE

Cisco WebEx Advanced Recording Format player Vulnerable to buffer overflow

Trust: 0.8

sources: JVNDB: JVNDB-2013-003975

DESCRIPTION

Buffer overflow in Cisco WebEx Advanced Recording Format (ARF) player T27 LD before SP32 EP16, T27 L10N before SP32_ORION111, and T28 before T28.8 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted ARF file, aka Bug IDs CSCue74147 and CSCub28383. An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition. This issue is being tracked by Cisco Bug IDs CSCue74147 and CSCub28383. The following versions are affected: 27.11.26, 27.21.10, 27.25.10, 27.32.1, 27.32.10, 28.4, 28.0.0

Trust: 1.98

sources: NVD: CVE-2013-1116 // JVNDB: JVNDB-2013-003975 // BID: 62159 // VULHUB: VHN-61118

AFFECTED PRODUCTS

vendor:ciscomodel:webex advanced recording format playerscope:eqversion:27.11.26

Trust: 1.6

vendor:ciscomodel:webex advanced recording format playerscope:eqversion:27.21.10

Trust: 1.6

vendor:ciscomodel:webex advanced recording format playerscope:eqversion:27.32.1

Trust: 1.6

vendor:ciscomodel:webex advanced recording format playerscope:eqversion:27.25.10

Trust: 1.6

vendor:ciscomodel:webex advanced recording format playerscope:eqversion:28.0.0

Trust: 1.6

vendor:ciscomodel:webex advanced recording format playerscope:eqversion:sp32_orion111

Trust: 0.8

vendor:ciscomodel:webex advanced recording format playerscope:ltversion:t28

Trust: 0.8

vendor:ciscomodel:webex advanced recording format playerscope:ltversion:t27 l10n

Trust: 0.8

vendor:ciscomodel:webex advanced recording format playerscope:eqversion:sp32 ep16

Trust: 0.8

vendor:ciscomodel:webex advanced recording format playerscope:eqversion:t28.8

Trust: 0.8

vendor:ciscomodel:webex advanced recording format playerscope:ltversion:t27 ld

Trust: 0.8

sources: JVNDB: JVNDB-2013-003975 // CNNVD: CNNVD-201309-013 // NVD: CVE-2013-1116

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2013-1116
value: HIGH

Trust: 1.0

NVD: CVE-2013-1116
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201309-013
value: CRITICAL

Trust: 0.6

VULHUB: VHN-61118
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2013-1116
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-61118
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-61118 // JVNDB: JVNDB-2013-003975 // CNNVD: CNNVD-201309-013 // NVD: CVE-2013-1116

PROBLEMTYPE DATA

problemtype:CWE-119

Trust: 1.9

sources: VULHUB: VHN-61118 // JVNDB: JVNDB-2013-003975 // NVD: CVE-2013-1116

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201309-013

TYPE

buffer overflow

Trust: 0.6

sources: CNNVD: CNNVD-201309-013

CONFIGURATIONS

sources: JVNDB: JVNDB-2013-003975

PATCH

title:cisco-sa-20130904-webexurl:http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130904-webex

Trust: 0.8

title:Cisco WebEx ARF Player Memory Corruption Vulnerabilityurl:http://tools.cisco.com/security/center/viewIpsSignature.x?signatureId=2735&signatureSubId=0&softwareVersion=6.0&releaseVersion=S739

Trust: 0.8

title:30532url:http://tools.cisco.com/security/center/viewAlert.x?alertId=30532

Trust: 0.8

title:cisco-sa-20130904-webexurl:http://www.cisco.com/cisco/web/support/JP/111/1119/1119807_cisco-sa-20130904-webex-j.html

Trust: 0.8

sources: JVNDB: JVNDB-2013-003975

EXTERNAL IDS

db:NVDid:CVE-2013-1116

Trust: 2.8

db:BIDid:62159

Trust: 1.0

db:JVNDBid:JVNDB-2013-003975

Trust: 0.8

db:CISCOid:20130904 MULTIPLE VULNERABILITIES IN THE CISCO WEBEX RECORDING FORMAT AND ADVANCED RECORDING FORMAT PLAYERS

Trust: 0.6

db:CNNVDid:CNNVD-201309-013

Trust: 0.6

db:VULHUBid:VHN-61118

Trust: 0.1

sources: VULHUB: VHN-61118 // BID: 62159 // JVNDB: JVNDB-2013-003975 // CNNVD: CNNVD-201309-013 // NVD: CVE-2013-1116

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20130904-webex

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2013-1116

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2013-1116

Trust: 0.8

url:http://www.securityfocus.com/bid/62159

Trust: 0.6

url:http://www.cisco.com/

Trust: 0.3

sources: VULHUB: VHN-61118 // BID: 62159 // JVNDB: JVNDB-2013-003975 // CNNVD: CNNVD-201309-013 // NVD: CVE-2013-1116

CREDITS

Microsoft Vulnerability Research (MSVR)

Trust: 0.9

sources: BID: 62159 // CNNVD: CNNVD-201309-013

SOURCES

db:VULHUBid:VHN-61118
db:BIDid:62159
db:JVNDBid:JVNDB-2013-003975
db:CNNVDid:CNNVD-201309-013
db:NVDid:CVE-2013-1116

LAST UPDATE DATE

2024-08-14T14:14:21.402000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-61118date:2013-09-06T00:00:00
db:BIDid:62159date:2013-09-04T00:00:00
db:JVNDBid:JVNDB-2013-003975date:2013-09-09T00:00:00
db:CNNVDid:CNNVD-201309-013date:2013-09-09T00:00:00
db:NVDid:CVE-2013-1116date:2013-09-06T13:34:20.950

SOURCES RELEASE DATE

db:VULHUBid:VHN-61118date:2013-09-06T00:00:00
db:BIDid:62159date:2013-09-04T00:00:00
db:JVNDBid:JVNDB-2013-003975date:2013-09-09T00:00:00
db:CNNVDid:CNNVD-201309-013date:2013-09-05T00:00:00
db:NVDid:CVE-2013-1116date:2013-09-06T11:15:37.153