Description
The dirapi.dll module in Adobe Shockwave Player before 11.5.9.620 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a Director movie with an IFWV chunk with a size field of 0, which is used in the calculation of a file offset and causes invalid data to be used as a loop counter, triggering a heap-based buffer overflow, a different vulnerability than CVE-2010-2587 and CVE-2010-2588.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2010-4162 | The dirapi.dll module in Adobe Shockwave Player before 11.5.9.620 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a Director movie with an IFWV chunk with a size field of 0, which is used in the calculation of a file offset and causes invalid data to be used as a loop counter, triggering a heap-based buffer overflow, a different vulnerability than CVE-2010-2587 and CVE-2010-2588. |
References
History
No history.
Status: PUBLISHED
Assigner: adobe
Published:
Updated: 2024-08-07T03:34:37.536Z
Reserved: 2010-11-05T00:00:00.000Z
Link: CVE-2010-4188
No data.
Status : Modified
Published: 2011-02-10T16:00:12.863
Modified: 2026-04-29T01:13:23.040
Link: CVE-2010-4188
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD