RULE(RULE ID:309879)

Rule General Information
Release Date: 2012-02-21
Rule Name: Adobe Shockwave Player Director File Parsing integer overflow Vulnerability (CVE-2010-2876)
Severity:
CVE ID:
Rule Protection Details
Description: A code execution vulnerability exists in Adobe Shockwave player. The vulnerability is due to an integer overflow error while calculating the size value for heap memory allocation while parsing a FFFFFF88 record. Remote attackers can exploit this vulnerability by enticing target users to open a malicious DIR file using a vulnerable version of the product.
Impact: Remote code execution
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: CVE-2010-2876
Solutions
Update vendor's patch.