Oval Definition:oval:org.mitre.oval:def:11285
Revision Date:2014-11-10Version:47
Title:Denial of service (memory corruption) via a Director movie with a crafted rcsL chunk in the Director module (dirapi.dll) in Adobe Shockwave Player before 11.5.9.615
Description:The Director module (dirapi.dll) in Adobe Shockwave Player before 11.5.9.615 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a Director movie with a crafted rcsL chunk containing a field whose value is used as a pointer offset, as exploited in the wild in October 2010. NOTE: some of these details are obtained from third party information.
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2010-3653
Platform(s):Microsoft Windows 2000
Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Vista
Microsoft Windows XP
Product(s):Adobe Shockwave Player
Definition Synopsis
  • Version of either Macromedia or Adobe Shockwave Player is less than or equal to 11.5.8.612
  • Check if the version of Adobe Shockwave Player is less than or equal to 11.5.8.612
  • OR Check if the version of Macromedia Shockwave Player is less than or equal to 11.5.8.612
  • AND Adobe Shockwave Player is installed
  • BACK