CVE-2006-6885: Medium severity Macromedia Shockwave vulnerability
Published Dec 31, 2006
·Updated
An ActiveX control in SwDir.dll in Macromedia Shockwave 10 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long string in the swURL attribute.
Affected Software
1 affected component
Macromedia Shockwave=10
Event History
Dec 31, 2006
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Jan 5, 2007
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-6885?
CVE-2006-6885 is classified as a denial of service vulnerability.
2
How do I fix CVE-2006-6885?
To fix CVE-2006-6885, update Macromedia Shockwave to the latest version that addresses this vulnerability.
3
Which software is affected by CVE-2006-6885?
CVE-2006-6885 affects Macromedia Shockwave version 10.
4
What type of attack does CVE-2006-6885 enable?
CVE-2006-6885 enables remote attackers to crash Internet Explorer 7.
5
Can CVE-2006-6885 be exploited via the web?
Yes, CVE-2006-6885 can be exploited through a malicious web page using a long string in the swURL attribute.