Skip to main content

Adobe Shockwave Player Multiple Code Execution Vulnerabilities

Last Update Date: 28 Jan 2011 Release Date: 13 May 2010 4401 Views

RISK: Medium Risk

Multiple vulnerabilities have been identified in Adobe Shockwave Player, which could be exploited by remote attackers to compromise a vulnerable system. These issues are caused by memory corruptions, integer and buffer overflows, array indexing, and signedness errors when processing malformed Shockwave or Director files, which could be exploited by attackers to execute arbitrary code by tricking a user into visiting a specially crafted web page.


Impact

  • Remote Code Execution

System / Technologies affected

  • Adobe Shockwave Player version 11.5.6.606 and prior (Windows and Macintosh)

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

Upgrade to Adobe Shockwave Player version 11.5.7.609 :
http://get.adobe.com/shockwave/


Vulnerability Identifier


Source


Related Link