Adobe Shockwave Player CVE-2011-2112 Multiple Remote Vulnerabilities
BID:48278
Info
Adobe Shockwave Player CVE-2011-2112 Multiple Remote Vulnerabilities
| Bugtraq ID: | 48278 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2011-2112 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 14 2011 12:00AM |
| Updated: | Jun 14 2011 12:00AM |
| Credit: | Luigi Auriemma, Donato Ferrante, Carsten Eiram of Secunia Research and binaryproof |
| Vulnerable: |
Adobe Shockwave Player 11.5.7 .609 Adobe Shockwave Player 11.5.6 .606 Adobe Shockwave Player 11.5.2 .606 Adobe Shockwave Player 11.5.2 .602 Adobe Shockwave Player 11.5.1 .601 Adobe Shockwave Player 11.5 .601 Adobe Shockwave Player 11.5 .600 Adobe Shockwave Player 11.5 .596 Adobe Shockwave Player 11.5.9.620 Adobe Shockwave Player 11.5.9.615 Adobe Shockwave Player 11.5.8.612 Adobe Shockwave Player 11.5.0.595 Adobe Shockwave Player 11.0.3.471 Adobe Shockwave Player 11.0.0.456 |
| Not Vulnerable: |
Adobe Shockwave Player 11.6.0.626 |
Discussion
Adobe Shockwave Player CVE-2011-2112 Multiple Remote Vulnerabilities
Adobe Shockwave Player is prone to multiple remote vulnerabilities because it fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit these issues to execute arbitrary malicious code in the context of a user running an application that uses the affected library. Failed exploit attempts will likely crash the application.
Adobe Shockwave Player versions 11.5.9.620 and earlier for Windows and Macintosh are vulnerable.
NOTE: These issues were previously covered in BID 48270 (Adobe Shockwave Player APSB11-17 Multiple Remote Vulnerabilities) but have been given their own record to better document them.
Adobe Shockwave Player is prone to multiple remote vulnerabilities because it fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit these issues to execute arbitrary malicious code in the context of a user running an application that uses the affected library. Failed exploit attempts will likely crash the application.
Adobe Shockwave Player versions 11.5.9.620 and earlier for Windows and Macintosh are vulnerable.
NOTE: These issues were previously covered in BID 48270 (Adobe Shockwave Player APSB11-17 Multiple Remote Vulnerabilities) but have been given their own record to better document them.
Exploit / POC
Adobe Shockwave Player CVE-2011-2112 Multiple Remote Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Adobe Shockwave Player CVE-2011-2112 Multiple Remote Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Adobe Shockwave Player CVE-2011-2112 Multiple Remote Vulnerabilities
References:
References:
- Adobe Flash Homepage (Adobe)
- Adobe Shockwave CASt Chunk Parsing Remote Code Execution Vulnerability (Zero Day Initiative)
- Adobe Shockwave DEMX Chunk Multiple Field Parsing Remote Code Execution Vulnerab (Zero Day Initiative)
- Adobe Shockwave TextXtra Text Element Parsing Remote Code Execution Vulnerabilit (Zero Day Initiative)
- Adobe Shockwave xtcL Chunk Parsing Integer Overflow Remote Code Execution Vulner (Zero Day Initiative)
- APSB11-17 Security update available for Adobe Shockwave Player (Adobe)
- CVE-2011-2112 : Adobe Shockwave Player DEMX Input Validation Vulnerability (Secunia)