Adobe Shockwave Player Multiple Remote Code Execution Vulnerabilities
RISK: Medium Risk
Multiple vulnerabilities have been identified in Adobe Shockwave Player, which could be exploited by remote attackers to compromise a vulnerable system. These issues are caused by memory corruptions and buffer overflow errors in the "DIRAPI.dll" and "IML32.dll" modules when processing malformed Shockwave or Director files, which could be exploited by attackers to execute arbitrary code by tricking a user into visiting a specially crafted web page.
Impact
- Remote Code Execution
System / Technologies affected
- Adobe Shockwave Player version 11.5.8.612 and prior (Windows and Macintosh)
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Upgrade to Adobe Shockwave Player version 11.5.9.615 :
http://get.adobe.com/shockwave/
Vulnerability Identifier
- CVE-2010-2581
- CVE-2010-2582
- CVE-2010-3653
- CVE-2010-3655
- CVE-2010-4084
- CVE-2010-4085
- CVE-2010-4086
- CVE-2010-4087
- CVE-2010-4088
- CVE-2010-4089
- CVE-2010-4090
Source
Related Link
Share with