Fortinet Discovers Multiple Adobe Shockwave Player Vulnerabilities (APSB10-12)
Summary:
Fortinet's FortiGuard Labs has discovered seven vulnerabilities in Adobe Shockwave Player that could compromise the affected system.
Impact:
System Compromise
Risk:
Critical
Affected Software:
For a list of Adobe versions affected, please see the references below.
Additional Information:
Memory Corruption occurs when Shockwave Player parses ".dir" media file that can lead to exploitation. (CVE-2010-1280,CVE-2010-1286,CVE-2010-1287,CVE-2010-1289,CVE-2010-1290,CVE-2010-1291).
Heap overflow that can lead to exploitation. (CVE-2010-1288).
Vulnerabilities are being exploited to run malicious code on the affected system.