Adobe Shockwave Player 'DIRAPI.dll' Remote Code Execution Vulnerability
BID:40076
Info
Adobe Shockwave Player 'DIRAPI.dll' Remote Code Execution Vulnerability
| Bugtraq ID: | 40076 |
| Class: | Unknown |
| CVE: |
CVE-2010-0128 |
| Remote: | Yes |
| Local: | No |
| Published: | May 11 2010 12:00AM |
| Updated: | May 13 2010 08:51PM |
| Credit: | Nahuel Riva |
| Vulnerable: |
Adobe Shockwave Player 11.5.6 .606 Adobe Shockwave Player 11.5.2 .606 Adobe Shockwave Player 11.5.2 .602 Adobe Shockwave Player 11.5.1 .601 Adobe Shockwave Player 11.5 .601 Adobe Shockwave Player 11.5 .600 Adobe Shockwave Player 11.5 .596 Adobe Director 11.5 Adobe Director 11.0.0.426 |
| Not Vulnerable: |
Adobe Shockwave Player 11.5.7 .609 Adobe Director 11.5.7.609 |
Discussion
Adobe Shockwave Player 'DIRAPI.dll' Remote Code Execution Vulnerability
Adobe Shockwave Player is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the user running the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
Adobe Shockwave Player 11.5.6.606 and prior are vulnerable.
NOTE: This issue was previously discussed in BID 40066 (Adobe Shockwave Player APSB10-12 Multiple Remote Vulnerabilities) but has been given its own record to better document it.
Adobe Shockwave Player is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the user running the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
Adobe Shockwave Player 11.5.6.606 and prior are vulnerable.
NOTE: This issue was previously discussed in BID 40066 (Adobe Shockwave Player APSB10-12 Multiple Remote Vulnerabilities) but has been given its own record to better document it.
Exploit / POC
Adobe Shockwave Player 'DIRAPI.dll' Remote Code Execution Vulnerability
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Core Security Technologies has developed a working commercial proof-of-concept for this issue. This proof of concept is not otherwise publicly available or known to be circulating in the wild.
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Core Security Technologies has developed a working commercial proof-of-concept for this issue. This proof of concept is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Adobe Shockwave Player 'DIRAPI.dll' Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Adobe Shockwave Player 'DIRAPI.dll' Remote Code Execution Vulnerability
References:
References:
- Adobe Homepage (Adobe)
- Adobe Security Advisory APSB10-12 (Adobe)
- [CORE-2010-0405] Adobe Director Invalid Read ([email protected])
- Secunia Research: Adobe Shockwave Player Signedness Error Vulnerability (Secunia Research
) - Adobe Director DIRAPI.DLL Memory Corruption Vulnerability (Core)
- CORE-2010-0405 Adobe Director DIRAPI.DLL Invalid Read Vulnerability (Core)
- Secunia Research: Adobe Shockwave Player Signedness Error Vulnerability (Secunia)