RULE(RULE ID:322449)

Rule General Information
Release Date: 2019-07-06
Rule Name: Cisco WebEx UCF atucfobj.dll ActiveX NewObject Buffer Overflow Vulnerability (CVE-2008-3558)
Severity:
CVE ID:
Rule Protection Details
Description: Stack-based buffer overflow in the WebexUCFObject ActiveX control in atucfobj.dll in Cisco WebEx Meeting Manager before 20.2008.2606.4919 allows remote attackers to execute arbitrary code via a long argument to the NewObject method.
Impact: A buffer overflow vulnerability can be triggered by an attacker in the context of the vulnerable product. Further attacks includes arbitrary code execution and denial of service.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: SecurityFocusBID:30578
ExploitDB:6220
http://lists.grok.org.uk/pipermail/full-disclosure/2008-August/063692.html
http://www.cisco.com/en/US/products/products_security_advisory09186a00809e2006.shtml
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://www.cisco.com/warp/public/707/cisco-sa-20080814-webex.shtml