Adobe Shockwave Player Multiple Code Execution Vulnerabilities
RISK: Medium Risk
Multiple vulnerabilities have been identified in Adobe Shockwave Player, which could be exploited by remote attackers to compromise a vulnerable system. These issues are caused by memory corruptions, integer and buffer overflows, array indexing, and signedness errors when processing malformed Shockwave or Director files, which could be exploited by attackers to execute arbitrary code by tricking a user into visiting a specially crafted web page.
Impact
- Remote Code Execution
System / Technologies affected
- Adobe Shockwave Player version 11.5.6.606 and prior (Windows and Macintosh)
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
Upgrade to Adobe Shockwave Player version 11.5.7.609 :
http://get.adobe.com/shockwave/
Vulnerability Identifier
- CVE-2010-0127
- CVE-2010-0128
- CVE-2010-0129
- CVE-2010-0130
- CVE-2010-0986
- CVE-2010-0987
- CVE-2010-1280
- CVE-2010-1281
- CVE-2010-1282
- CVE-2010-1283
- CVE-2010-1284
- CVE-2010-1286
- CVE-2010-1287
- CVE-2010-1288
- CVE-2010-1289
- CVE-2010-1290
- CVE-2010-1291
- CVE-2010-1292
Source
Related Link
Share with