Adobe Shockwave Player 'DIRAPIX.dll' File Remote Memory Corruption Vulnerability
15 Apr. 2012
Summary
This allows remote attackers to execute arbitrary code via unknown vectors that trigger memory corruption. NOTE: due to conflicting information and use of the same CVE identifier by the vendor, ZDI, and TippingPoint, it is not clear whether this issue is related to use of an uninitialized pointer, an incorrect pointer offset calculation, or both.
Vulnerable Systems:
* Adobe Shockwave Player 11.5.7 .609
* Adobe Shockwave Player 11.5.6 .606
* Adobe Shockwave Player 11.5.2 .606
* Adobe Shockwave Player 11.5.2 .602
* Adobe Shockwave Player 11.5.1 .601
* Adobe Shockwave Player 11.5 .601
* Adobe Shockwave Player 11.5 .600
* Adobe Shockwave Player 11.5 .596
Immune Systems:
* Adobe Shockwave Player 11.5.8.612
Adobe Shockwave Player is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue to execute arbitrary code in the context of the user running the affected application. Failed attacks may cause a denial-of-service condition.
Vendor Status:
Adobe as issued an update for this vulnerablity.