Release date:
Updated on:
Affected Systems:
Adobe Shockwave Player 11.x
Unaffected system:
Adobe Shockwave Player 11.6.1.629
Description:
--------------------------------------------------------------------------------
Bugtraq id: 49102
Cve id: CVE-2010-4308, CVE-2010-4309, CVE-2011-2420, CVE-2011-2421, CVE-2011-2422
Adobe Shockwave Player is a plug-in software for playing web pages created by Director Shockwave Studio.
Adobe Shockwave Player has multiple memory corruption vulnerabilities. Remote attackers can exploit these vulnerabilities to crash affected applications or execute arbitrary code in them.
<* Source: Mark Yason
Aaron Portnoy (aportnoy@ccs.neu.edu)
Logan Brown
Andrzej Dyjak
Link: http://www.adobe.com/support/security/bulletins/apsb11-19.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Adobe
-----
Adobe has released a Security Bulletin (APSB11-19) and patches for this:
APSB11-19: Security update available for Adobe Shockwave Player
Link: http://www.adobe.com/support/security/bulletins/apsb11-19.html