Adobe Shockwave Player Director File Memory Corruption Remote Code Execution Vulnerability
10 Apr. 2012
Summary
Thisallows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a malformed chunk in a Director file, a different vulnerability than CVE-2011-0555, CVE-2010-4093, CVE-2010-4190, CVE-2010-4191, CVE-2010-4192, and CVE-2010-4306.
Vulnerable Systems:
* Adobe Shockwave Player 11.5.7 .609
* Adobe Shockwave Player 11.5.6 .606
* Adobe Shockwave Player 11.5.2 .606
* Adobe Shockwave Player 11.5.2 .602
* Adobe Shockwave Player 11.5.1 .601
* Adobe Shockwave Player 11.5 .601
* Adobe Shockwave Player 11.5 .600
* Adobe Shockwave Player 11.5 .596
* Adobe Shockwave Player 11.5.9.615
* Adobe Shockwave Player 11.5.8.612
* Adobe Shockwave Player 11.5.0.595
* Adobe Shockwave Player 11.0.3.471
* Adobe Shockwave Player 11.0.0.456
* Adobe Shockwave Player 11
Immune Systems:
* Adobe Shockwave Player 11.5.9.620
Adobe Shockwave Player is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code within the context of the user running the affected application. Failed attempts will likely cause a denial-of-service condition.
Versions prior to Shockwave Player 11.5.9.620 are vulnerable.
Vendor Status:
Adobe as issued an update for this vulnerablity.