Vulnerable Systems:
* Cisco WebEx Player prior to T27LC SP22 on Windows
* Cisco WebEx Player prior to T27LC SP22 on Mac OS X
* Cisco WebEx Player prior to T27LC SP22 on Linux
* Cisco WebEx Player prior to T27LB SP21 EP3 on Windows
* Cisco WebEx Player prior to T27LB SP21 EP3 on Mac OS X
* Cisco WebEx Player prior to T27LB SP21 EP3 on Linux
The WebEx meeting service is a hosted multimedia conferencing solution that is managed and maintained by Cisco WebEx. The WRF and ARF file formats are used to store WebEx meeting recordings that have been recorded on the computer of an on-line meeting attendee. The players are applications that are used to play back and edit recording files (files with .wrf and .arf extensions). The recording players can be automatically installed when the user accesses a recording file that is hosted on a WebEx server (for stream playback mode). The recording players can also be manually installed after downloading the application from www.webex.com/downloadplayer.html to play back recording files locally (for offline playback mode).
Multiple buffer overflow vulnerabilities exist in the WRF and ARF players. The vulnerabilities may lead to a crash of the player application or, in some cases, remote code execution could occur.
To exploit one of these vulnerabilities, the player application would need to open a malicious WRF or ARF file. An attacker may be able to accomplish this exploit by providing the malicious recording file directly to users (for example, by using e-mail) or by directing a user to a malicious web page. The vulnerability cannot be triggered by users who are attending a WebEx meeting.
Patch Availability:
Cisco recommends that users upgrade to the most current version of the player that is available from: http://www.webex.com/downloadplayer.html