Adobe Shockwave Player Multiple Remote Code Execution and Denial of Service Vulnerabilities
BID:36905
Info
Adobe Shockwave Player Multiple Remote Code Execution and Denial of Service Vulnerabilities
| Bugtraq ID: | 36905 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2009-3244 CVE-2009-3463 CVE-2009-3464 CVE-2009-3465 CVE-2009-3466 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 03 2009 12:00AM |
| Updated: | Nov 04 2009 05:27PM |
| Credit: | Nicolas Joly of VUPEN Security |
| Vulnerable: |
Adobe Shockwave Player 11.5.1 .601 Adobe Shockwave Player 11.5 .601 Adobe Shockwave Player 11.5 .600 Adobe Shockwave Player 11.5 .596 Adobe Shockwave Player 10.2 .023 Adobe Shockwave Player 10 |
| Not Vulnerable: |
Adobe Shockwave Player 11.5.2 .602 |
Discussion
Adobe Shockwave Player Multiple Remote Code Execution and Denial of Service Vulnerabilities
Adobe Shockwave Player is prone to a multiple remote code-execution and denial-of-service vulnerabilities.
Attackers can exploit these issues to execute arbitrary code in the context of the currently logged-in user and to cause denial-of-service conditions.
Versions prior to Shockwave Player 11.5.2.602 for Microsoft Windows and Apple Mac OS X are vulnerable.
Adobe Shockwave Player is prone to a multiple remote code-execution and denial-of-service vulnerabilities.
Attackers can exploit these issues to execute arbitrary code in the context of the currently logged-in user and to cause denial-of-service conditions.
Versions prior to Shockwave Player 11.5.2.602 for Microsoft Windows and Apple Mac OS X are vulnerable.
Exploit / POC
Adobe Shockwave Player Multiple Remote Code Execution and Denial of Service Vulnerabilities
Working commercial exploits are available through VUPEN Security - Exploit and PoCs Service for the vulnerabilities documented by the following CVEs:
CVE-2009-3463
CVE-2009-3464
CVE-2009-3465
CVE-2009-3466
These exploits are not otherwise publicly available or known to be circulating in the wild.
Working commercial exploits are available through VUPEN Security - Exploit and PoCs Service for the vulnerabilities documented by the following CVEs:
CVE-2009-3463
CVE-2009-3464
CVE-2009-3465
CVE-2009-3466
These exploits are not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Adobe Shockwave Player Multiple Remote Code Execution and Denial of Service Vulnerabilities
Solution:
The vendor has released an advisory and updates. Please see the references for details.
Solution:
The vendor has released an advisory and updates. Please see the references for details.
References
Adobe Shockwave Player Multiple Remote Code Execution and Denial of Service Vulnerabilities
References:
References:
- Adobe Shockwave Player Homepage (Adobe)
- VUPEN Security - Adobe Shockwave Player Multiple Code Execution Vulnerabilities ("VUPEN Security Research"
) - APSB09-16 Security updates available for Shockwave Player (Adobe)