Adobe Shockwave Player 3D Object Parsing Memory Corruption Vulnerability
BID:40077
Info
Adobe Shockwave Player 3D Object Parsing Memory Corruption Vulnerability
| Bugtraq ID: | 40077 |
| Class: | Design Error |
| CVE: |
CVE-2010-1283 |
| Remote: | Yes |
| Local: | No |
| Published: | May 11 2010 12:00AM |
| Updated: | May 14 2010 03:28PM |
| Credit: | An anonymous researcher reported through TippingPoint's Zero Day Initiative; Chaouki Bekrar of VUPEN Security |
| Vulnerable: |
Adobe Shockwave Player 11.5.6 .606 Adobe Shockwave Player 11.5.2 .606 Adobe Shockwave Player 11.5.2 .602 Adobe Shockwave Player 11.5.1 .601 Adobe Shockwave Player 11.5 .601 Adobe Shockwave Player 11.5 .600 Adobe Shockwave Player 11.5 .596 |
| Not Vulnerable: |
Adobe Shockwave Player 11.5.7 .609 |
Discussion
Adobe Shockwave Player 3D Object Parsing Memory Corruption Vulnerability
Adobe Shockwave Player is prone to a memory-corruption vulnerability.
Attackers can exploit this issue to crash the affected application and execute arbitrary code within the context of the affected application.
Adobe Shockwave Player 11.5.6.606 and prior are vulnerable.
NOTE: This issue was previously discussed in BID 40066 (Adobe Shockwave Player APSB10-12 Multiple Remote Vulnerabilities) but has been given its own record to better document it.
Adobe Shockwave Player is prone to a memory-corruption vulnerability.
Attackers can exploit this issue to crash the affected application and execute arbitrary code within the context of the affected application.
Adobe Shockwave Player 11.5.6.606 and prior are vulnerable.
NOTE: This issue was previously discussed in BID 40066 (Adobe Shockwave Player APSB10-12 Multiple Remote Vulnerabilities) but has been given its own record to better document it.
Exploit / POC
Adobe Shockwave Player 3D Object Parsing Memory Corruption Vulnerability
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
A commercial proof of concept is available through VUPEN Security - Exploit and PoCs Service. This proof of concept is not otherwise publicly available or known to be circulating in the wild.
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
A commercial proof of concept is available through VUPEN Security - Exploit and PoCs Service. This proof of concept is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Adobe Shockwave Player 3D Object Parsing Memory Corruption Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Adobe Shockwave Player 3D Object Parsing Memory Corruption Vulnerability
References:
References:
- Adobe Homepage (Adobe)
- Adobe Security Advisory APSB10-12 (Adobe)
- VUPEN Security Research - Adobe Shockwave 3D Blocks Field Code Execution Vulnera ("VUPEN Security Research"
) - ZDI-10-088: Adobe Shockwave Player 3D Parsing Memory Corruption Vulnerability (Zero Day Initiative )