Skip to main content

Adobe Shockwave Player rcsL Chunk Memory Corruption Vulnerability

Last Update Date: 28 Jan 2011 Release Date: 22 Oct 2010 4737 Views

RISK: Medium Risk

A vulnerability has been identified in Adobe Shockwave Player, which could be exploited by remote attackers to execute arbitrary code. This issue is caused by a memory corruption error in the Director (dirapi.dll) module when processing and calculating offsets while parsing "rcsL" chunks in a Director file, which could allow remote attackers to compromise a vulnerable system by tricking a user into visiting a specially crafted web page.


Impact

  • Remote Code Execution

System / Technologies affected

  • Adobe Shockwave Player version 11.5.8.612 and prior

Solutions

  • There is no patch available for this vulnerability currently.


Vulnerability Identifier


Source


Related Link