Macromedia Shockwave Player ActiveX Control Buffer Overflow Vulnerability
BID:16791
Info
Macromedia Shockwave Player ActiveX Control Buffer Overflow Vulnerability
| Bugtraq ID: | 16791 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 23 2006 12:00AM |
| Updated: | Feb 24 2006 06:22PM |
| Credit: | Discovered by Peter Vreugdenhil. |
| Vulnerable: |
Macromedia Shockwave 8.5.1 r106 Macromedia Shockwave 8.5.1 r105 Macromedia Shockwave 8.0 Macromedia Shockwave 6.0 Macromedia Shockwave 5.0 Macromedia Shockwave 4.0 Macromedia Shockwave 3.0 Macromedia Shockwave 2.0 Macromedia Shockwave 1.0 Macromedia Shockwave 10.1.0.11 |
| Not Vulnerable: | |
Discussion
Macromedia Shockwave Player ActiveX Control Buffer Overflow Vulnerability
Macromedia Shockwave Player is prone to a buffer overflow when a particular ActiveX control is passed malicious parameters. Attackers can exploit this vulnerability to crash the application or to potentially execute arbitrary code.
Macromedia Shockwave Player versions 10.1.0.11 and earlier are vulnerable.
Macromedia Shockwave Player is prone to a buffer overflow when a particular ActiveX control is passed malicious parameters. Attackers can exploit this vulnerability to crash the application or to potentially execute arbitrary code.
Macromedia Shockwave Player versions 10.1.0.11 and earlier are vulnerable.
Exploit / POC
Macromedia Shockwave Player ActiveX Control Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution / Fix
Macromedia Shockwave Player ActiveX Control Buffer Overflow Vulnerability
Solution:
This issue has been addressed by Adobe. Reportedly, no action needs to be taken by users to correct this vulnerability.
Solution:
This issue has been addressed by Adobe. Reportedly, no action needs to be taken by users to correct this vulnerability.
References
Macromedia Shockwave Player ActiveX Control Buffer Overflow Vulnerability
References:
References: