Zero-Day Advisory
Fortinet Discovers Adobe Shockwave Player Vulnerability
Summary
Fortinet's FortiGuard Labs has discovered a memory corruption vulnerability in Adobe Shockwave Player.
Solutions
FortiGuard Labs released the following FortiGate IPS signature which covers this specific vulnerability:Adobe.Shockwave.Player.Unspecified.Chunk.Remote.Code.Execution
Released Jun 14, 2011
Users should apply the solution provided by Adobe.
Additional Information
The memory corruption vulnerability can be triggered when parsing a crafted dir file that contains malformed field.Acknowledgement
Honggang Ren of Fortinet's FortiGuard Labs