Adobe Shockwave Player Director File Parsing Invalid Offset Remote Code Execution Vulnerability
BID:40078
Info
Adobe Shockwave Player Director File Parsing Invalid Offset Remote Code Execution Vulnerability
| Bugtraq ID: | 40078 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2010-1281 |
| Remote: | Yes |
| Local: | No |
| Published: | May 11 2010 12:00AM |
| Updated: | May 11 2010 12:00AM |
| Credit: | An anonymous researcher via TippingPoint's Zero Day Initiative |
| Vulnerable: |
Adobe Shockwave Player 11.5.6 .606 Adobe Shockwave Player 11.5.2 .606 Adobe Shockwave Player 11.5.2 .602 Adobe Shockwave Player 11.5.1 .601 Adobe Shockwave Player 11.5 .601 Adobe Shockwave Player 11.5 .600 Adobe Shockwave Player 11.5 .596 |
| Not Vulnerable: |
Adobe Shockwave Player 11.5.7 .609 |
Discussion
Adobe Shockwave Player Director File Parsing Invalid Offset Remote Code Execution Vulnerability
Adobe Shockwave Player is prone to a remote code-execution vulnerability caused by a heap-based memory-corruption error while parsing Director files.
Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts may cause a denial-of-service condition.
Versions prior to Shockwave Player 11.5.7.609 are vulnerable.
Note: This issue was previously covered in BID 40066 (Adobe Shockwave Player APSB10-12 Multiple Remote Vulnerabilities); it has been given its own record to better document it.
Adobe Shockwave Player is prone to a remote code-execution vulnerability caused by a heap-based memory-corruption error while parsing Director files.
Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts may cause a denial-of-service condition.
Versions prior to Shockwave Player 11.5.7.609 are vulnerable.
Note: This issue was previously covered in BID 40066 (Adobe Shockwave Player APSB10-12 Multiple Remote Vulnerabilities); it has been given its own record to better document it.
Exploit / POC
Adobe Shockwave Player Director File Parsing Invalid Offset Remote Code Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Adobe Shockwave Player Director File Parsing Invalid Offset Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Adobe Shockwave Player Director File Parsing Invalid Offset Remote Code Execution Vulnerability
References:
References:
- Adobe Security Advisory APSB10-12 (Adobe)
- Adobe Shockwave Player Homepage (Adobe)
- ZDI-10-087: Adobe Shockwave Invalid Offset Memory Corruption Remote Code Executi (ZDI Disclosures
) - ZDI-10-087 Adobe Shockwave Invalid Offset Memory Corruption Remote Code Executio (Zero Day Initiative)