Zero-Day Advisory
Fortinet Discovers Multiple Adobe Shockwave Player Vulnerabilities
Summary
Fortinet's FortiGuard Labs has discovered multiple code execution vulnerabilities in Adobe Shockwave Player.
Solutions
FortiGuard Labs released the following FortiGate IPS signature which covers this specific vulnerability:Adobe.Shockwave.Multiple.Code.Execution
Released Aug 15, 2012
Users should apply the solution provided by Adobe.
Additional Information
These vulnerabilities can be triggered by opening maliciously crafted dir file that contains malformed field. They could allow an attacker to execute arbitrary code on the affected system.
Acknowledgement
Honggang Ren of Fortinet's FortiGuard Labs