Skip to main content

Adobe Shockwave Player Multiple Remote Code Execution Vulnerabilities

Last Update Date: 28 Jan 2011 Release Date: 1 Nov 2010 4759 Views

RISK: Medium Risk

Multiple vulnerabilities have been identified in Adobe Shockwave Player, which could be exploited by remote attackers to compromise a vulnerable system. These issues are caused by memory corruptions and buffer overflow errors in the "DIRAPI.dll" and "IML32.dll" modules when processing malformed Shockwave or Director files, which could be exploited by attackers to execute arbitrary code by tricking a user into visiting a specially crafted web page.


Impact

  • Remote Code Execution

System / Technologies affected

  • Adobe Shockwave Player version 11.5.8.612 and prior (Windows and Macintosh)

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link