Shockwave Player < 11.5.6.606 Multiple Vulnerabilities (APSB10-03)

high Nessus Plugin ID 44094

Language:

Synopsis

The remote Windows host contains a web browser plugin that is affected by multiple vulnerabilities.

Description

The remote Windows host contains a version of Adobe's Shockwave Player that is earlier than 11.5.6.606. As such, it is potentially affected by multiple issues :

- A buffer overflow vulnerability that could potentially lead to code execution. (CVE-2009-4002)

- Multiple integer overflow vulnerabilities that could lead to code execution. (CVE-2009-4003)

Solution

Upgrade to Adobe Shockwave version 11.5.6.606 or later.

See Also

https://secuniaresearch.flexerasoftware.com/secunia_research/2009-61/

https://secuniaresearch.flexerasoftware.com/secunia_research/2009-62/

https://secuniaresearch.flexerasoftware.com/secunia_research/2009-63/

https://secuniaresearch.flexerasoftware.com/secunia_research/2010-1/

http://www.adobe.com/support/security/bulletins/apsb10-03.html

Plugin Details

Severity: High

ID: 44094

File Name: shockwave_player_apsb10-03.nasl

Version: 1.14

Type: local

Agent: windows

Family: Windows

Published: 1/20/2010

Updated: 11/15/2018

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 9.3

Temporal Score: 6.9

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/a:adobe:shockwave_player

Required KB Items: SMB/Registry/Enumerated

Exploit Ease: No known exploits are available

Patch Publication Date: 1/19/2010

Vulnerability Publication Date: 1/19/2010

Reference Information

CVE: CVE-2009-4002, CVE-2009-4003

BID: 37870, 37872

CWE: 119, 189

Secunia: 37888