|
|||
Rule General Information |
---|
Release Date: | 2013-03-01 | |
Rule Name: | EXPLOIT Adobe Shockwave Director PAMI Chunk Parsing Memory Corruption (CVE-2010-2872) | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | A code execution vulnerability exists in Adobe Shockwave player. The vulnerability is due to insufficient sanitation while parsing an offset value in PAMI record of a Director file. Remote attackers can exploit this vulnerability by enticing target users to open a malicious DIR file using a vulnerable version of the product. | |
Impact: | Remote code execution | |
Affected OS: | Windows | |
Reference: | CVE-2010-2872 SecurityFocusBID:42679 SecurityAdvisory:SA41065 APSB10-20 ZeroDayInitiative:ZDI-10-161 |
|
Solutions |
---|
Update vendor's patch. |