CVE-2010-1292
Last modified
CVE-2010-1292 is a vulnerability of currently unknown severity. The implementation of pami RIFF chunk parsing in Adobe Shockwave Player before 11.5.7.609 does not validate a certain value from a file before using it in file-pointer calculations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .dir (aka Director) file.. EPSS estimates a 6.37% chance of exploitation in the next 30 days.
Description
The implementation of pami RIFF chunk parsing in Adobe Shockwave Player before 11.5.7.609 does not validate a certain value from a file before using it in file-pointer calculations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .dir (aka Director) file.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Shockwave Player | <= 11.5.6.606 |
| Adobe | Shockwave Player | 1.0 |
| Adobe | Shockwave Player | 2.0 |
| Adobe | Shockwave Player | 3.0 |
| Adobe | Shockwave Player | 4.0 |
| Adobe | Shockwave Player | 5.0 |
| Adobe | Shockwave Player | 6.0 |
| Adobe | Shockwave Player | 8.0 |
| Adobe | Shockwave Player | 8.5.1 |
| Adobe | Shockwave Player | 9 |
| Adobe | Shockwave Player | 10.1.0.11 |
| Adobe | Shockwave Player | 11.0.0.456 |
| Adobe | Shockwave Player | 11.5.0.595 |
| Adobe | Shockwave Player | 11.5.0.596 |
| Adobe | Shockwave Player | 11.5.1.601 |
| Adobe | Shockwave Player | 11.5.2.602 |
| Adobe | Shockwave Player | All versions |
References
- http://secunia.com/advisories/38751Vendor Advisory
- http://www.adobe.com/support/security/bulletins/apsb10-12.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/archive/1/511242/100/0/threadedThird Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2010/1128Patch, Vendor Advisory
- http://www.zerodayinitiative.com/advisories/ZDI-10-089/Third Party Advisory, VDB Entry
- http://secunia.com/advisories/38751Vendor Advisory
- http://www.adobe.com/support/security/bulletins/apsb10-12.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/archive/1/511242/100/0/threadedThird Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2010/1128Patch, Vendor Advisory
- http://www.zerodayinitiative.com/advisories/ZDI-10-089/Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-1292?
How severe is CVE-2010-1292?
How do I fix CVE-2010-1292?
Are you affected by CVE-2010-1292?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
