{ "id": "CVE-2010-3270", "sourceIdentifier": "cve@mitre.org", "published": "2011-02-02T23:00:32.127", "lastModified": "2018-10-10T20:01:32.443", "vulnStatus": "Modified", "descriptions": [ { "lang": "en", "value": "Stack-based buffer overflow in Cisco WebEx Meeting Center T27LB before SP21 EP3 and T27LC before SP22 allows user-assisted remote authenticated users to execute arbitrary code by providing a crafted .atp file and then disconnecting from a meeting. NOTE: since this is a site-specific issue with no expected action for consumers, it might be REJECTed." }, { "lang": "es", "value": "Desbordamiento de b\u00fafer basado en pila en Cisco WebEx Meeting Center T27LB anteriores a SP21 EP3 y T27LC anteriores a SP22, permite a usuarios remotos asistidos por usuarios a ejecutar c\u00f3digo de su elecci\u00f3n mediante un fichero .atp manipulado y desconect\u00e1ndolo de la conferencia. NOTA: Dado que es una cuesti\u00f3n exclusiva de las especificaciones del sitio sin efecto concreto para los usuarios, podr\u00eda ser rechazada.\r\n" } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:H/Au:M/C:C/I:C/A:C", "accessVector": "NETWORK", "accessComplexity": "HIGH", "authentication": "MULTIPLE", "confidentialityImpact": "COMPLETE", "integrityImpact": "COMPLETE", "availabilityImpact": "COMPLETE", "baseScore": 6.8 }, "baseSeverity": "MEDIUM", "exploitabilityScore": 3.2, "impactScore": 10.0, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-119" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:cisco:webex_meeting_center:27.0:*:*:*:*:*:*:*", "matchCriteriaId": "451DE486-CE76-4B7A-9451-4F0BBD63C96B" } ] } ] } ], "references": [ { "url": "http://securitytracker.com/id?1025015", "source": "cve@mitre.org" }, { "url": "http://tools.cisco.com/security/center/viewAlert.x?alertId=22355", "source": "cve@mitre.org" }, { "url": "http://www.coresecurity.com/content/webex-atp-and-wrf-overflow-vulnerabilities", "source": "cve@mitre.org" }, { "url": "http://www.securityfocus.com/archive/1/516095/100/0/threaded", "source": "cve@mitre.org" }, { "url": "http://www.securityfocus.com/bid/46078", "source": "cve@mitre.org" }, { "url": "http://www.vupen.com/english/advisories/2011/0260", "source": "cve@mitre.org", "tags": [ "Vendor Advisory" ] } ] }