PT-2010-1322 · Adobe · Shockwave Player

Published

2010-01-21

·

Updated

2018-10-10

·

CVE-2009-4003

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Adobe Shockwave Player versions prior to 11.5.6.606
Description The issue is related to multiple integer overflows that can lead to the execution of arbitrary code. This can occur through various means, including an unspecified block type in a Shockwave file, which results in a heap-based buffer overflow, or through an unspecified 3D block in a Shockwave file, leading to memory corruption. Additionally, a crafted 3D model in a Shockwave file can cause heap memory corruption.
Recommendations For Adobe Shockwave Player versions prior to 11.5.6.606, update to version 11.5.6.606 or later to resolve the issue. As a temporary workaround, consider avoiding the use of unspecified block types and 3D blocks in Shockwave files, as well as crafted 3D models, until the update is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-4003

Affected Products

Shockwave Player