Adobe Shockwave Player CVE-2011-2113 Multiple Remote Code Execution Vulnerabilities
BID:48306
Info
Adobe Shockwave Player CVE-2011-2113 Multiple Remote Code Execution Vulnerabilities
| Bugtraq ID: | 48306 |
| Class: | Unknown |
| CVE: |
CVE-2011-2113 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 14 2011 12:00AM |
| Updated: | Mar 01 2012 11:50PM |
| Credit: | Aniway and Luigi Auriemma |
| Vulnerable: |
Adobe Shockwave Player 11.5.7 .609 Adobe Shockwave Player 11.5.6 .606 Adobe Shockwave Player 11.5.2 .606 Adobe Shockwave Player 11.5.2 .602 Adobe Shockwave Player 11.5.1 .601 Adobe Shockwave Player 11.5 .601 Adobe Shockwave Player 11.5 .600 Adobe Shockwave Player 11.5 .596 Adobe Shockwave Player 11.5.9.620 Adobe Shockwave Player 11.5.9.615 Adobe Shockwave Player 11.5.8.612 Adobe Shockwave Player 11.5.0.595 Adobe Shockwave Player 11.0.3.471 Adobe Shockwave Player 11.0.0.456 Adobe Shockwave Player 11 |
| Not Vulnerable: |
Adobe Shockwave Player 11.6.0.626 |
Discussion
Adobe Shockwave Player CVE-2011-2113 Multiple Remote Code Execution Vulnerabilities
Adobe Shockwave Player is prone to multiple remote code-execution vulnerabilities.
Attackers can exploit these issues to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
Versions prior to Adobe Shockwave Player 11.6.0.626 are vulnerable.
NOTE: This issue was previously documented in BID 48270 (Adobe Shockwave Player APSB11-17 Multiple Remote Vulnerabilities) but has been given its own record to better document it.
Adobe Shockwave Player is prone to multiple remote code-execution vulnerabilities.
Attackers can exploit these issues to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
Versions prior to Adobe Shockwave Player 11.6.0.626 are vulnerable.
NOTE: This issue was previously documented in BID 48270 (Adobe Shockwave Player APSB11-17 Multiple Remote Vulnerabilities) but has been given its own record to better document it.
Exploit / POC
Adobe Shockwave Player CVE-2011-2113 Multiple Remote Code Execution Vulnerabilities
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Adobe Shockwave Player CVE-2011-2113 Multiple Remote Code Execution Vulnerabilities
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Adobe Shockwave Player CVE-2011-2113 Multiple Remote Code Execution Vulnerabilities
References:
References:
- Adobe Homepage (Adobe)
- Adobe Shockwave iml32.dll DEMX Remote Code Execution Vulnerability (TippingPoint Zero Day Initiative)
- ZDI-11-211: Adobe Shockwave Shockwave 3d Asset.x32 DEMX Chunk (zdi-disclosures)
- ZDI-11-222: Adobe Shockwave Shockwave 3d Asset.x32 DEMX Chunk (zdi-disclosures)
- Adobe Shockwave Shockwave 3d Asset.x32 DEMX Chunk 0xFFFFFF49 Field Remote Code E (Zero Day Initiative)
- Adobe Shockwave Shockwave 3d Asset.x32 DEMX Chunk Substructure Count Remote Code (Zero Day Initiative)
- Security update available for Adobe Shockwave Player (Adobe)