[Other] Mehrere Schwachstellen im Adobe Shockwave Player - APSB11-19

—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA1

Liebe Kolleginnen und Kollegen,

soeben erreichte uns nachfolgende Warnung. Wir geben diese Informationen
unveraendert an Sie weiter.

CVE-2010-4308 / CVE-2010-4309 / CVE-2011-2419 / CVE-2011-2420 /
CVE-2011-2421 / CVE-2011-2422 / CVE-2011-2423 – Mehrere Schwachstellen
im Adobe Shockwave Player

Im Shockwave Player von Adobe existieren mehrere Schwachstellen, die
durch eine Korrumpierung des Speichers entfernten Angreifern
schlimmstenfalls erlauben, beliebigen Code mit den Rechten des Nutzers
auszufuehren. Fuer die Ausnutzung ist es notwendig, dass ein Nutzer dazu
gebracht wird, eine bestimmte Webseite aufzurufen. Betroffen sind unter
anderem die Komponenten IML32.dll, Dirapi.dll, msvcr90.dll und
Textra.x32.

Betroffen sind die folgenden Software Pakete und Plattformen:

Shockwave Player vor Version 11.6.1.629

Alle Windows-Plattformen und Macintosh-Plattformen, auf denen die
Software lauffaehig ist.

Vom Hersteller werden ueberarbeitete Pakete zur Verfuegung gestellt.

(c) der deutschen Zusammenfassung bei DFN-CERT Services GmbH; die
Verbreitung, auch auszugsweise, ist nur unter Hinweis auf den Urheber,
DFN-CERT Services GmbH, und nur zu nicht kommerziellen Zwecken
gestattet.

Mit freundlichen Gruessen,
Timo Schulz

– —
Timo Schulz, M.Sc. (Incident Response Team)

DFN-CERT Services GmbH, https://www.dfn-cert.de, Phone +49 40 808077-590
Sitz / Register: Hamburg, AG Hamburg, HRB 88805, Ust-IdNr.: DE 232129737
Sachsenstrasse 5, 20097 Hamburg/Germany, CEO: Dr. Klaus-Peter Kossakowski

Automatische Warnmeldungen: https://www.cert.dfn.de/autowarn

Security update available for Adobe Shockwave Player

Release date: August 9, 2011
Vulnerability identifier: APSB11-19
CVE number: CVE-2010-4308, CVE-2010-4309, CVE-2011-2419, CVE-2011-2420, CVE-2011-2421, CVE-2011-2422, CVE-2011-2423.
Platform: Windows and Macintosh

Summary

Critical vulnerabilities have been identified in Adobe Shockwave Player 11.6.0.626 and earlier versions on the Windows and Macintosh operating systems. These vulnerabilities could allow an attacker, who successfully exploits these vulnerabilities, to run malicious code on the affected system. Adobe recommends users of Adobe Shockwave Player 11.6.0.626 and earlier versions update to Adobe Shockwave Player 11.6.1.629 using the instructions provided below.

Affected software versions

Shockwave Player11.6.0.626 and earlier versions for Windows and Macintosh

Solution

Adobe recommends users of Adobe Shockwave Player 11.6.0.626 and earlier versions upgrade to the newest version 11.6.1.629 available here: http://get.adobe.com/shockwave/.

Severity rating

Adobe categorizes these as critical updates and recommends affected users update their installations to the newest versions.

Details

Critical vulnerabilities have been identified in Adobe Shockwave Player 11.6.0.626 and earlier versions on the Windows and Macintosh operating systems. These vulnerabilities could allow an attacker, who successfully exploits these vulnerabilities, to run malicious code on the affected system. Adobe recommends users of Adobe Shockwave Player 11.6.0.626 and earlier versions update to Adobe Shockwave Player 11.6.1.629 using the instructions provided in the “Solution” section above.
This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-4308).
This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-4309).
This update resolves a memory corruption vulnerability in the IML32.dll component that could lead to remote code execution (CVE-2011-2419).
This update resolves a memory corruption vulnerability that could lead to remote code execution (CVE-2011-2420).
This update resolves a memory corruption when Shockwave Player parses a .dir media file in the Dirapi.dll component that could lead to code execution. (CVE-2011-2421).
This update resolves a memory corruption vulnerability in the Textra.x32 component that could lead to remote code execution (CVE-2011-2422).
This update resolves a memory corruption in the msvcr90.dll component that could lead to remote code execution (CVE-2011-2423).

Acknowledgments

Adobe would like to thank the following individuals and organizations for reporting the relevant issues and for working with Adobe to help protect our customers:

* Mark Yason ofIBM_X-Force (CVE-2010-4308, CVE-2010-4309 ).
* Aaron Portnoy and Logan Brown, TippingPoint_DVLabs (CVE-2011-2419)
* Andrzej Dyjak of PJIIT (CVE-2011- 2420, CVE-2011-2422, CVE-2011-2423)
* Honggang Ren of Fortinet’sFortiGuard_Labs (CVE-2011- 2421)

—–BEGIN PGP SIGNATURE—–
Version: GnuPG v2.0.16 (GNU/Linux)

iQEcBAEBAgAGBQJOQpf5AAoJEJtyb8U7iGZBnUsH/iW/9P4mE66jw7MEFXhYuJHe
GiB+KOWejHX9GB6D7xPaI0iDA23pFDcB3oluHW/fcYK1poqBAq2YfKfxF1r0rMyU
meOTzlbYESdjv7IWi/1ftZHPAfbYFnLI53WW5uYNrAX5yXHHaHGzHmFlNwNKwCM8
D8m6PsaEPOTvywDaF7+d0zsmUTGvcK58jjAXGt2ftueXJJQrZ++zS3GKkpBO3Znl
HdCt2QvmPIcNhBoLYEe2JOyDCRSyrPZGBALx3xtybPjD66+worhrIjcj4a9BaJ0r
W1qvL+QNSkGrI97pS/TUfZEljKOEPeaMOXd2G/9wTlywS13IFO6l3SlbJu9KEIM=
=J3rR
—–END PGP SIGNATURE—–

Nach oben