Adobe Shockwave Player 3D Assets Module Integer Overflow Remote Code Execution Vulnerability
10 Apr. 2011
Summary
This allows remote attackers to execute arbitrary code via a Director movie with a large count value in 3D assets type 0xFFFFFF45 record, which triggers a "faulty allocation" and memory corruption.
Vulnerable Systems:
* Adobe Shockwave Player 11.5.7 .609
* Adobe Shockwave Player 11.5.6 .606
* Adobe Shockwave Player 11.5.2 .606
* Adobe Shockwave Player 11.5.2 .602
* Adobe Shockwave Player 11.5.1 .601
* Adobe Shockwave Player 11.5 .601
* Adobe Shockwave Player 11.5 .600
* Adobe Shockwave Player 11.5 .596
* Adobe Shockwave Player 11.5.9.615
* Adobe Shockwave Player 11.5.8.612
* Adobe Shockwave Player 11.5.0.595
* Adobe Shockwave Player 11.0.3.471
* Adobe Shockwave Player 11.0.0.456
* Adobe Shockwave Player 11
Immune Systems:
* Adobe Shockwave Player 11.5.9.620
Adobe Shockwave Player is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code within the context of the user running the affected application. Failed attempts will likely cause a denial-of-service condition.
Versions prior to Shockwave Player 11.5.9.620 are vulnerable.
Vendor Status:
Adobe as issued an update for this vulnerablity.