Get a Pentest and security assessment of your IT network.

Advisories

iDEFENSE Security Advisory 2010-08-24.1

iDefense Security Advisory 08.24.10 – Remote exploitation of a memory corruption vulnerability in Adobe Systems Inc.’s Shockwave Player could allow an attacker to execute arbitrary code with the privileges of the current user. The vulnerability takes place during the processing of a tSAC chunk within an Adobe Director file. A length value is read from the tSAC chunk and a signed comparison is made against the length value. If the length value is negative, a memory address is incorrectly calculated and a null byte is written to the memory address. This condition may lead to arbitrary code execution. Shockwave Player 11.5.7.609 and earlier versions for Windows and Macintosh are vulnerable.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/93131/08.24.10-1.txt

Source: https://packetstormsecurity.com/files/93131/iDEFENSE-Security-Advisory-2010-08-24.1.html

Related posts
Advisories

CSIS2005-1.txt

Advisories

Secunia Security Advisory 17625

Advisories

Secunia Security Advisory 20411

Advisories

Secunia Security Advisory 23300