ITSS-Advisory : MEDIUM : Adobe : Shockwave Player : Arbitrary Code Execution
THREAT LEVEL
============
Medium.
INFORMATION
===========
On 23 June 2009, Adobe released an updated version of Shockwave Player.
This new version (11.5.0.600) fixes a vulnerability in earlier versions.
Accessing specially crafted content could result in arbitrary code
execution on an affected computer. More information is available at:
http://www.adobe.com/support/security/bulletins/apsb09-08.html
AFFECTED PLATFORMS
==================
Computers of various operating systems running Adobe Shockwave Player
versions prior to 11.5.0.600.
ACTION
======
Administrators of affected computers are advised to review the
bulletin, test and apply relevant updates.
From the bulletin:
- - - - - - - - - - - - - - - - - - - - - - - - - - - -
Adobe recommends Shockwave Player users on Windows uninstall Shockwave
version 11.5.0.596 and earlier on their systems, restart, and install
Shockwave version 11.5.0.600, available here:
http://get.adobe.com/shockwave/
- - - - - - - - - - - - - - - - - - - - - - - - - - - -
|