Web Design - Publish.com
Publish.com Ziff-Davis Enterprise  
SEARCH · ONLINE MEDIA · MOBILE · WEB DESIGN · GRAPHICS TOOLS · PRINTING · PHOTO · TIPS · OPINIONS
Home arrow Web Design arrow Adobe Fixes Shockwave Code Execution Flaw
Adobe Fixes Shockwave Code Execution Flaw
By Ryan Naraine

Rate This Article:
Add This Article To:
A "critical" security hole in the Macromedia Shockwave Installer could put users at risk of code execution attacks.

A security flaw in Adobe Systems' Macromedia Shockwave Installer could put millions of PC users at risk of code execution attacks, the company warned in an advisory.

The flaw, which carries a "critical" rating, affects Shockwave Player 10.1.0.11 and earlier versions. According to Adobe's advisory, the vulnerability occurs only during the installation process, and current users do not need to take action.

"Customers downloading and installing the latest Shockwave Player are also no longer vulnerable with the updated Shockwave Player ActiveX installer," Adobe officials said.

The company credited Tipping Point's Zero Day Initiative with reporting the issue, which is caused due to a boundary error in the Shockwave Installer ActiveX control. It sets up a scenario where a malicious hacker can trigger a stack-based buffer overflow via overly long values passed in two specific parameters to the control.

Security alerts aggregator Secunia warned that successful exploitation allows arbitrary code execution, but it requires that users are tricked into visiting a malicious Web site that prompts them to install Shockwave Player.

Users should only install Shockwave Player directly from Adobe's Web site, Secunia officials said.

For advice on how to secure your network and applications, as well as the latest security news, visit Ziff Davis Internet's Security IT Hub.

A separate alert from the Zero Day Initiative said that the target user is not required to have fully completed an installation of Shockwave to be vulnerable.

"This specific flaw exists within the ActiveX control with CLSID 166B1BCA-3F9C-11CF-8075-444553540000. Specifying large values for two specific parameters to this control results in an exploitable stack based buffer overflow," company officials added.

The Macromedia Shockwave player, which was originally designed for use in Web-based movies and animations, is popular in the online gaming industry. It is marketed as a browser plug-in alongside the more popular Macromedia Flash Player.

The Shockwave patch is the second from Adobe this year. Earlier this month, the company pushed out security updates to cover a potentially serious code execution flaw that affected Adobe Creative Suite 2, Adobe Photoshop CS2 and Adobe Illustrator CS2 on both Windows and Mac OS platforms.

Check out eWEEK.com's for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzer's Weblog.


Discuss Adobe Fixes Shockwave Code Execution Flaw
 
>>> Be the FIRST to comment on this article!
 

 
 
>>> More Web Design Articles          >>> More By Ryan Naraine
 


Buyer's Guide
Explore hundreds of products in our Publish.com Buyer's Guide.
Web design
Content management
Graphics Software
Streaming Media
Video
Digital photography
Stock photography
Web development
View all >

ADVERTISEMENT


FREE ZIFF DAVIS ENTERPRISE ESEMINARS AT ESEMINARSLIVE.COM
  • Dec 10, 4 p.m. ET
    Eliminate the Drawbacks of Traditional Backup/Replication for Linux
    with Michael Krieger. Sponsored by InMage
  • Dec 11, 1 p.m. ET
    Data Modeling and Metadata Management with PowerDesigner
    with Joel Shore. Sponsored by Sybase
  • Dec 12, 12 p.m. ET
    Closing the IT Business Gap: Monitoring the End-User Experience
    with Michael Krieger. Sponsored by Compuware
  • Dec 12, 2 p.m. ET
    Enabling IT Consolidation
    with Michael Krieger. Sponsored by Riverbed & VMWare
  • VTS
    Join us on Dec. 19 for Discovering Value in Stored Data & Reducing Business Risk. Join this interactive day-long event to learn how your enterprise can cost-effectively manage stored data while keeping it secure, compliant and accessible. Disorganized storage can prevent your enterprise from extracting the maximum value from information assets. Learn how to organize enterprise data so vital information assets can help your business thrive. Explore policies, strategies and tactics from creation through deletion. Attend live or on-demand with complimentary registration!
    FEATURED CONTENT
    IT LINK DISCUSSION - MIGRATION
    A Windows Vista® migration introduces new and unique challenges to any IT organization. It's important to understand early on whether your systems, hardware, applications and end users are ready for the transition.
    Join the discussion today!



    .NAME Charging For Whois
    Whois has always been a free service, but the .NAME registry is trying to change that.
    Read More >>

    Sponsored by Ziff Davis Enterprise Group

    NEW FROM ZIFF DAVIS ENTERPRISE


    Delivering the latest technology news & reviews straight to your handheld device

    Now you can get the latest technology news & reviews from the trusted editors of eWEEK.com on your handheld device
    mobile.eWEEK.com

     


    RSS 2.0 Feed


    internet
    rss graphic Publish.com
    rss graphic Google Watch

    Video Interviews


    streaming video
    Designing Apps for Usability
    DevSource interviews usability pundit Dr. Jakob Nielsen on everything from the proper attitude for programmers to the importance of prototyping in design to the reasons why PDF, Flash and local search engines can hurt more than they help.
    ADVERTISEMENT