Multiple Vulnerabilities in Adobe Shockwave Player

Number: AV10-047
Date: 29 October 2010

Purpose

The purpose of this advisory is to raise awareness of multiple vulnerabilities in Adobe Shockwave Player for which a security update is now available.

Assessment

Multiple vulnerabilities have been identified in Shockwave Player, which, if successfully exploited, could allow malicious code to run on the affected system by exploiting various memory corruption and buffer overflow conditions. Some of these vulnerabilities are rated critical by the vendor.

CVE References: CVE-2010-2581, CVE-2010-2582, CVE-2010-3653, CVE-2010-3655, CVE-2010-4084, CVE-2010-4085, CVE-2010-4086, CVE-2010-4087, CVE-2010-4088, CVE-2010-4089, CVE-2010-4090

Exploit details were posted for CVE-2010-3653 and functioning exploit code is available in tools such as Metasploit. This vulnerability can be exploited by tricking the user into opening a crafted Director movie file (DIR or DCR) or by following a link to a malicious site hosting the malicious file. If the Shockwave Player is not installed, the user may be prompted to install it. Adobe reports that this issue is being exploited in the wild.

Affected Versions

Adobe Shockwave Player 11.5.8.612 and earlier versions for Windows and Macintosh operating systems

Suggested action

Adobe recommends users of Adobe Shockwave Player 11.5.8.612 and earlier versions upgrade to the newest version 11.5.9.615.

CCIRC recommends that systems administrators identify affected products in their environment and follow their patch management process accordingly.

References

Note to Readers

In support of Public Safety's mission to build a safe and resilient Canada, CCIRC's mandate is to help ensure the security and resilience of the vital non-federal government cyber systems that underpin Canada's national security, public safety and economic prosperity. As Canada's computer security incident response team, CCIRC is Canada's national coordination centre for the prevention and mitigation of, preparedness for, response to, and recovery from cyber incidents on non-federal government systems. It does this by providing authoritative advice and support, and coordinating information sharing and incident response.

Please note, CCIRC PGP key has recently been updated.
http://www.publicsafety.gc.ca/cnt/ntnl-scrt/cbr-scrt/_fl/CCIRCPublicPGPKey.txt

For general information, please contact Public Safety Canada's Public Affairs division at:

Telephone: 613-944-4875 or 1-800-830-3118
Fax: 613-998-9589
E-mail: ps.communications-communications.sp@canada.ca

Date modified: