PT-2010-1944 · Adobe · Shockwave Player+1
Published
2010-05-13
·
Updated
2022-04-22
·
CVE-2010-0128
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Adobe Shockwave Player versions prior to 11.5.7.609
Adobe Director versions prior to 11.5.7.609
Description
The issue is caused by an integer signedness error in the dirapi.dll component. This error can be triggered by a crafted .dir file, leading to a denial of service due to memory corruption, or potentially allowing the execution of arbitrary code through an invalid read operation.
Recommendations
For Adobe Shockwave Player versions prior to 11.5.7.609, update to version 11.5.7.609 or later.
For Adobe Director versions prior to 11.5.7.609, update to version 11.5.7.609 or later.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Director
Shockwave Player