CERT-In Vulnerability Note
CIVN-2013-0211
Memory Corruption Vulnerabilities in Adobe Shockwave Player
Original Issue Date:December 12, 2013
Severity Rating: HIGH
Systems Affected
- Adobe Shockwave Player 12.0.6.147 & prior for windows and Macintosh
Overview
Memory corruption vulnerabilities have been reported in Adobe shockwave player which could allow a remote attacker to execute arbitrary code on the target system.
Description
Multiple vulnerabilities exist in adobe shockwave player which could lead to arbitrary code execution.
An unauthenticated remote attacker could exploit this vulnerability by creating specially crafted content which when loaded by the target user will lead to memory corruption error to execute arbitrary code on the target system with the privileges of currently logged in user.
Solution
Apply appropriate patches as mentioned in
APSB13-29
Vendor Information
Adobe
http://helpx.adobe.com/security/products/shockwave/apsb13-29.html
References
Adobe
http://helpx.adobe.com/security/products/shockwave/apsb13-29.html
Cisco
http://tools.cisco.com/security/center/viewAlert.x?alertId=32111
Security tracker
http://www.securitytracker.com/id/1029458
Secunia
http://secunia.com/advisories/55952/
CVE Name
CVE-2013-5333
CVE-2013-5334
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|