Release date:
Updated on:
Affected Systems:
Adobe Shockwave Player 11.5.8.612
Description:
--------------------------------------------------------------------------------
Bugtraq id: 44291
Cve id: CVE-2010-3653
Adobe Shockwave Player is a plug-in software dedicated to playing web pages created by Director Shockwave Studio.
Shockwave has an array index error when processing some record values in the rcsL block. If you are cheated to open a specially crafted Director file, any dword in the memory will be used as a function pointer, this completely controls the affected systems.
<* Source: Abysssec
Link: http://secunia.com/advisories/41932/
Http://www.exploit-db.com/exploits/15296/
Http://www.adobe.com/support/security/advisories/apsa10-04.html
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Www.exploit-db.com/sploits/adobe_shockwave_director_rcsl_chunk_memory_policuption.zip
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Adobe
-----
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.adobe.com