SB2011081202 - Multiple vulnerabilities in Adobe Shockwave Player



SB2011081202 - Multiple vulnerabilities in Adobe Shockwave Player

Published: August 12, 2011 Updated: August 11, 2020

Security Bulletin ID SB2011081202
Severity
High
Patch available
YES
Number of vulnerabilities 7
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 7 secuirty vulnerabilities.


1) Buffer overflow (CVE-ID: CVE-2011-2419)

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

IML32.dll in Adobe Shockwave Player before 11.6.1.629 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.


2) Buffer overflow (CVE-ID: CVE-2011-2420)

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

Adobe Shockwave Player before 11.6.1.629 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.


3) Buffer overflow (CVE-ID: CVE-2011-2421)

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

Dirapi.dll in Adobe Shockwave Player before 11.6.1.629 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .dir media file.


4) Buffer overflow (CVE-ID: CVE-2011-2422)

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

Textra.x32 in Adobe Shockwave Player before 11.6.1.629 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.


5) Buffer overflow (CVE-ID: CVE-2011-2423)

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

msvcr90.dll in Adobe Shockwave Player before 11.6.1.629 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.


6) Buffer overflow (CVE-ID: CVE-2010-4308)

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

Adobe Shockwave Player before 11.6.1.629 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-4309.


7) Buffer overflow (CVE-ID: CVE-2010-4309)

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

Adobe Shockwave Player before 11.6.1.629 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-4308.


Remediation

Install update from vendor's website.