CVE-2010-3270
Description
Stack-based buffer overflow in Cisco WebEx Meeting Center T27LB before SP21 EP3 and T27LC before SP22 allows user-assisted remote authenticated users to execute arbitrary code by providing a crafted .atp file and then disconnecting from a meeting. NOTE: since this is a site-specific issue with no expected action for consumers, it might be REJECTed.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| cisco | webex_meeting_center | 27.0 | |
References
- http://securitytracker.com/id?1025015
- http://tools.cisco.com/security/center/viewAlert.x?alertId=22355
- http://www.coresecurity.com/content/webex-atp-and-wrf-overflow-vulnerabilities
- http://www.securityfocus.com/archive/1/516095/100/0/threaded
- http://www.securityfocus.com/bid/46078
- http://www.vupen.com/english/advisories/2011/0260
- http://securitytracker.com/id?1025015
- http://tools.cisco.com/security/center/viewAlert.x?alertId=22355
- http://www.coresecurity.com/content/webex-atp-and-wrf-overflow-vulnerabilities
- http://www.securityfocus.com/archive/1/516095/100/0/threaded
- http://www.securityfocus.com/bid/46078
- http://www.vupen.com/english/advisories/2011/0260
CWEs
CWE-119
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.