This application requires Javascript for optimal performance.

Adobe.Shockwave.Player.Dir.File.Parsing.Integer.Overflow

Release Date

Jan 20, 2010

Severity

critical

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt to exploit a remote code-execution vulnerability in Adobe Shockwave Player which could be exploited by opening a specially crafted ".dir" file.

Affected Products

Shockwave Player 11.5.2.602 and earlier versions for Windows and Macintosh

Recommended Actions

Refer to vendor's advisory for updates or patches:
http://www.adobe.com/support/security/bulletins/apsb10-03.html

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2009-4003

Reference/s

http://www.adobe.com/support/security/bulletins/apsb10-03.html
http://www.securityfocus.com/bid/37872 (BugTraq)

Reference: VID-18126