Adobe Shockwave Player rcsL Chunk Remote Memory Corruption Vulnerability
10 Apr. 2012
Summary
This allows remote attackers to cause a denial of service (heap memory corruption) or execute arbitrary code via a crafted movie, related to a "pointer offset vulnerability."
Vulnerable Systems:
* Adobe Shockwave Player 11.5.7 .609
* Adobe Shockwave Player 11.5.6 .606
* Adobe Shockwave Player 11.5.2 .606
* Adobe Shockwave Player 11.5.2 .602
* Adobe Shockwave Player 11.5.1 .601
* Adobe Shockwave Player 11.5 .601
* Adobe Shockwave Player 11.5 .600
* Adobe Shockwave Player 11.5 .596
Immune Systems:
* Adobe Shockwave Player 11.5.8.612
Adobe Shockwave Player is prone to a remote memory-corruption vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the user running the affected application. Failed attacks may cause a denial-of-service condition.
Adobe Shockwave Player 11.5.7.609 and prior are vulnerable.
Vendor Status:
Adobe as issued an update for this vulnerablity.