CVE-2010-2873 Information
Feb 14, 2021
cve
Description
Adobe Shockwave Player before 11.5.8.612 does not properly validate offset values in the rcsL RIFF chunks of (1) .DIR and (2) .DCR Director movies which allows remote attackers to cause a denial of service (heap memory corruption) or execute arbitrary code via a crafted movie.
Reference
http://www.adobe.com/support/security/bulletins/apsb10-20.html http://www.securityfocus.com/archive/1/513307/100/0/threaded http://www.securityfocus.com/bid/42682 http://www.securitytracker.com/id?1024361 http://www.vupen.com/english/advisories/2010/2176 http://www.zerodayinitiative.com/advisories/ZDI-10-162 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A12042
Share on: