—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA1
Liebe Kolleginnen und Kollegen,
soeben erreichte uns nachfolgende Warnung. Wir geben diese Informationen
unveraendert an Sie weiter.
CVE-2011-0317 / CVE-2011-0318 / CVE-2011-0319 / CVE-2011-0320 /
CVE-2011-0335 / CVE-2011-2108 / CVE-2011-2109 / CVE-2011-2110 /
CVE-2011-2111 / CVE-2011-2112 / CVE-2011-2113 / CVE-2011-2114 /
CVE-2011-2115 / CVE-2011-2116 / CVE-2011-2117 / CVE-2011-2118 /
CVE-2011-2119 / CVE-2011-2120 / CVE-2011-2121 / CVE-2011-2122 /
CVE-2011-2123 / CVE-2011-2124 / CVE-2011-2125 / CVE-2011-2126 /
CVE-2011-2127 / CVE-2011-2128 – Schwachstellen im Adobe Schockwave
Player
Im Adobe Shockwave Player sind mehrere Schwachstellen enthalten, welche
zu Integer- und Buffer Overflows fuehren koennen oder Fehler in der
Speicherverwaltung ausloesen. Ein entfernter Angreifer kann diese
Schwachstellen im schlimmsten Fall zum Ausfuehren von beliebigen
Befehlen mit Benutzerrechten ausnutzen, indem er diesen dazu bringt,
eine entsprechend aufgebaute Shockwave-Datei zu oeffnen.
Betroffen sind die folgenden Software Pakete und Plattformen:
Adobe Shockwave Player vor Version 11.6.0.626.
Alle Versionen von Microsoft Windows und Apple MacOS, fuer die
betroffene Versionen des Shockwave Players verfuegbar sind.
Vom Hersteller werden ueberarbeitete Pakete zur Verfuegung gestellt.
(c) der deutschen Zusammenfassung bei DFN-CERT Services GmbH; die
Verbreitung, auch auszugsweise, ist nur unter Hinweis auf den Urheber,
DFN-CERT Services GmbH, und nur zu nicht kommerziellen Zwecken
gestattet.
Mit freundlichen Gruessen,
Michael Groening, DFN-CERT
– —
Michael Groening (Incident Response Team)
DFN-CERT Services GmbH, https://www.dfn-cert.de, Phone +49 40 808077-590
Sitz / Register: Hamburg, AG Hamburg, HRB 88805, Ust-IdNr.: DE 232129737
Sachsenstrasse 5, 20097 Hamburg/Germany, CEO: Dr. Klaus-Peter Kossakowski
Automatische Warnmeldungen https://www.cert.dfn.de/autowarn
Security update available for Adobe Shockwave Player
Release date: June 14, 2011
Vulnerability identifier:APSB11-17
CVE number: CVE-2011-0317, CVE-2011-0318, CVE-2011-0319, CVE-2011-0320, CVE-2011-0335, CVE-2011-2108, CVE-2011-2109, CVE-2011-2111, CVE-2011-2112, CVE-2011-2113, CVE-2011-2114, CVE-2011-2115, CVE-2011-2116, CVE-2011-2117, CVE-2011-2118, CVE-2011-2119, CVE-2011-2120, CVE-2011-2121, CVE-2011-2122, CVE-2011-2123, CVE-2011-2124, CVE-2011-2125, CVE-2011-2126, CVE-2011-2127
Platform: Windows and Macintosh
Summary
Critical vulnerabilities have been identified in Adobe Shockwave Player 11.5.9.620 and earlier versions on the Windows and Macintosh operating systems. These vulnerabilities could allow an attacker, who successfully exploits these vulnerabilities, to run malicious code on the affected system. Adobe recommends users of Adobe Shockwave Player 11.5.9.620 and earlier versions update to Adobe Shockwave Player 11.6.0.626 using the instructions provided below.
Affected software versions
Shockwave Player 11.5.9.620 and earlier versions for Windows and Macintosh.
Solution
Adobe recommends users of Adobe Shockwave Player 11.5.9.620 and earlier versions upgrade to the newest version 11.6.0.626, available here: http://get.adobe.com/shockwave/
Severity rating
Adobe categorizes this as a critical update and recommends that users apply the latest update for their product installation by following the instructions in the “Solution” section above.
Details
Critical vulnerabilities have been identified in Adobe Shockwave Player 11.5.9.620 and earlier versions on the Windows and Macintosh operating systems. These vulnerabilities could allow an attacker, who successfully exploits these vulnerabilities, to run malicious code on the affected system. Adobe recommends users of Adobe Shockwave Player 11.5.9.620 and earlier versions update to Adobe Shockwave Player 11.6.0.626 using the instructions provided in the “Solution” section above.
This update resolves a memory corruption vulnerability in the Dirapi.dll component that could lead to code execution (CVE-2011-0317).
This update resolves a memory corruption vulnerability in the Dirapi.dll component that could lead to code execution (CVE-2011-0318).
This update resolves a memory corruption vulnerability in the Dirapi.dll component that could lead to code execution (CVE-2011-0319).
This update resolves a memory corruption vulnerability in the Dirapi.dll component that could lead to code execution (CVE-2011-0320).
This update resolves multiple memory corruption vulnerabilities in the Dirapi.dll component that could lead to code execution (CVE-2011-0335).
This update resolves a design flaw that could lead to code execution (CVE-2011-2108).
This update resolves multiple integer overflow vulnerabilities in the Dirapi.dll component that could lead to code execution (CVE-2011-2109).
This update resolves multiple memory corruption vulnerabilities in the IML32.dll component that could lead to code execution (CVE-2011-2111).
This update resolves multiple buffer overflow vulnerabilities in the IML32.dll component that could lead to code execution (CVE-2011-2112).
This update resolves multiple buffer overflow vulnerabilities in the Shockwave3DAsset component that could lead to code execution (CVE-2011-2113).
This update resolves multiple memory corruption vulnerabilities that could lead to code execution (CVE-2011-2114).
This update resolves multiple memory corruption vulnerabilities in the IML32.dll component that could lead to code execution (CVE-2011-2115).
This update resolves a memory corruption vulnerability in the IML32.dll component that could lead to code execution (CVE-2011-2116).
This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2011-2117).
This update resolves an input validation vulnerability in the FLV ASSET Xtra component that could lead to code execution (CVE-2011-2118).
This update resolves a memory corruption vulnerability in the Dirapi.dll component that could lead to code execution (CVE-2011-2119).
This update resolves an integer overflow vulnerability in the CursorAsset x32 component that could lead to code execution (CVE-2011-2120).
This update resolves an integer overflow vulnerability that could lead to code execution (CVE-2011-2121).
This update resolves a memory corruption vulnerability in the Dirapi.dll component that could lead to code execution (CVE-2011-2122).
This update resolves an integer overflow vulnerability in the Shockwave 3D Asset x32 component that could lead to code execution (CVE-2011-2123).
This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2011-2124).
This update resolves a buffer overflow vulnerability in the Dirapix.dll component that could lead to code execution (CVE-2011-2125).
This update resolves a buffer overflow vulnerability that could lead to code execution (CVE-2011-2126).
This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2011-2127).
This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2011-2128).
Acknowledgments
Adobe would like to thank the following individuals and organizations for reporting the relevant issues and for working with Adobe to help protect our customers:
* Honggang Ren of Fortinet’s_Fortiguard_Labs (CVE-2011-0335)
* Mark Yason of IBM X-Force Research, IBM_Security_Solutions (CVE-2011-0335)
* Carsten Eiram, Secunia_Research (CVE-2011-0335, CVE-2011-2111, CVE-2011-2112, CVE-2011-2117, CVE-2011-2124, CVE-2011-2128)
* Aaron Portnoy and Logan Brown, TippingPoint_DVLabs (CVE-2011-0335, CVE-2011-2111, CVE-2011-2116)
* Aniway (aniway.aniway@gmail.com) through TippingPoint’s_Zero_Day_Initiative (CVE-2011-0335, CVE-2011-2113, CVE-2011-2114)
* Luigi Auriemma through iDefense_Labs (CVE-2011-0335, CVE-2011-2115, CVE-2011-2123)
* Will Dormann of CERT (CVE-2011-2108)
* Luigi Auriemma through TippingPoint’s_Zero_Day_Initiative (CVE-2011-2109, CVE-2011-0335, CVE-2011-2111, CVE-2011-2112, CVE-2011-2119)
* Sebastian_Apelt through TippingPoint’s_Zero_Day_Initiative (CVE-2011-2109, CVE-2011-2120, CVE-2011-2121)
* Binaryproof through TippingPoint’s_Zero_Day_Initiative (CVE-2011-2112)
* Luigi Auriemma and Donato Ferrante through TippingPoint’s_Zero_Day_Initiative (CVE-2011-2112)
* Rodrigo_Rubira_Branco – Qualys Vulnerability & Malware Research Team (VMRT) (CVE-2011-2115)
* Donato Ferrante through TippingPoint’s_Zero_Day_Initiative(CVE-2011-2118)
* Celil Ünüver, SignalSEC and BGA (CVE-2011-2122)
—–BEGIN PGP SIGNATURE—–
Version: GnuPG v2.0.16 (GNU/Linux)
iQEcBAEBAgAGBQJN+cMVAAoJEJtyb8U7iGZBDPUH/1hgQWSMcfRbsa64SZXbb7pF
UxbjlrsqReYvWf7l+H5kSgMyfEjAhsf0FwMBGIhFae8+Qnv353QhjgRUWR2xmG4y
A8J0GBdw9ASiehJOQ0gIKRnc0WamsAgx02Tu2KUjp4AVOUFD5BixJ7c7/lQUanV1
dYr6aRvWsKN2h7MeKyod7ttqecyBtbhvhQQj0Cf2anKv0LvUgcuc4xegZttiY9kJ
DOJziEra2Mh9nW3o3WA42kYc+I3Sab3ycQvdIk8nYo+QeQzj0KA5pSzjD4KbhU0Y
93qf3LTnY3/Bm/+vaYn8PfKALqI1lrheMqFh+p2+5vgm770GNlejkRcNT3R8KfY=
=13Fw
—–END PGP SIGNATURE—–