Adobe Shockwave Player CVE-2011-0335 Multiple Remote Memory Corruption Vulnerabilities
BID:48275
Info
Adobe Shockwave Player CVE-2011-0335 Multiple Remote Memory Corruption Vulnerabilities
| Bugtraq ID: | 48275 |
| Class: | Unknown |
| CVE: |
CVE-2011-0335 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 14 2011 12:00AM |
| Updated: | Jun 16 2011 05:00PM |
| Credit: | Honggang Ren of Fortinet's Fortiguard Labs, Mark Yason of IBM X-Force Research, IBM Security Solutions, Carsten Eiram, Secunia Research, Aaron Portnoy and Logan Brown of TippingPoint DVLabs, Aniway through TippingPoint's Zero Day Initiative, Luigi Auriemma |
| Vulnerable: |
Adobe Shockwave Player 11.5.7 .609 Adobe Shockwave Player 11.5.6 .606 Adobe Shockwave Player 11.5.2 .606 Adobe Shockwave Player 11.5.2 .602 Adobe Shockwave Player 11.5.1 .601 Adobe Shockwave Player 11.5 .601 Adobe Shockwave Player 11.5 .600 Adobe Shockwave Player 11.5 .596 Adobe Shockwave Player 11.5.9.620 Adobe Shockwave Player 11.5.9.615 Adobe Shockwave Player 11.5.8.612 Adobe Shockwave Player 11.5.0.595 Adobe Shockwave Player 11.0.3.471 Adobe Shockwave Player 11.0.0.456 Adobe Shockwave Player 11 |
| Not Vulnerable: |
Adobe Shockwave Player 11.6.0.626 |
Discussion
Adobe Shockwave Player CVE-2011-0335 Multiple Remote Memory Corruption Vulnerabilities
Adobe Shockwave Player is prone to multiple remote memory-corruption vulnerabilities.
Attackers can exploit these issues to crash the affected application and to execute arbitrary code within the context of the affected application.
NOTE: These issues were previously covered in BID 48270 (Adobe Shockwave Player APSB11-17 Multiple Remote Vulnerabilities) but have been given their own record to better document them.
Versions prior to Adobe Shockwave Player 11.6.0.626 are vulnerable.
Adobe Shockwave Player is prone to multiple remote memory-corruption vulnerabilities.
Attackers can exploit these issues to crash the affected application and to execute arbitrary code within the context of the affected application.
NOTE: These issues were previously covered in BID 48270 (Adobe Shockwave Player APSB11-17 Multiple Remote Vulnerabilities) but have been given their own record to better document them.
Versions prior to Adobe Shockwave Player 11.6.0.626 are vulnerable.
Exploit / POC
Adobe Shockwave Player CVE-2011-0335 Multiple Remote Memory Corruption Vulnerabilities
Currently, we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Adobe Shockwave Player CVE-2011-0335 Multiple Remote Memory Corruption Vulnerabilities
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Adobe Shockwave Player CVE-2011-0335 Multiple Remote Memory Corruption Vulnerabilities
References:
References:
- Adobe Homepage (Adobe)
- Adobe Shockwave Missing Lctx Chunk Remote Code Execution Vulnerability (Zero Day Initiative)
- Adobe Shockwave rcsL Chunk 16-bit Field Parsing Remote Code Execution Vulnerabil (Zero Day Initiative)
- Adobe Shockwave rcsL Substructure Parsing Remote Code Execution Vulnerability (Zero Day Initiative)
- Adobe Shockwave Font Asset Heap Overflow Vulnerability (iDefense)
- Adobe Shockwave Lingo Script Opcodes Integer Signedness Vulnerability (iDefense)
- APSB11-17 Security update available for Adobe Shockwave Player (Adobe)
- TPTI-11-10 Adobe Shockwave dirapi.dll rcsL Chunk Parsing Remote Code Execution V (TippingPoint)
- ZDI-11-220 Adobe Shockwave Director File rcsL Chunk Multiple Opcode Parsing Remo (Zero Day Initiative)