|
|
| |
| This vulnerability allows remote attackers to execute code on vulnerable installations of Adobe's Shockwave Player. User interaction is required in that a user must visit a malicious web site. |
| |
Credit:
The information has been provided by Paul Kurczaba.
The original article can be found at: http://www.zerodayinitiative.com/advisories/ZDI-09-044
|
| |
Vulnerable Systems:
* Adobe Shockwave Player versions prior to 11.5.0.600
The specific flaw exists when the Shockwave player attempts to load a specially crafted Adobe Director File. When a malicious value is used during a memory dereference a possible 4-byte memory overwrite may
occur. Exploitation can lead to remote system compromise under the credentials of the currently logged in user.
Patch Availability:
Adobe has issued an update to correct this vulnerability. More details can be found at:
http://www.adobe.com/support/security/bulletins/apsb09-08.html
CVE Information:
CVE-2009-1860
Disclosure Timeline:
2008-05-12 - Vulnerability reported to vendor
2009-06-24 - Coordinated public release of advisory
|
|
|