First published: Wed Nov 04 2009(Updated: )
Array index error in Adobe Shockwave Player before 11.5.2.602 allows remote attackers to execute arbitrary code via crafted Shockwave content on a web site. NOTE: some of these details are obtained from third party information.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Shockwave Player | =5.0 | |
Adobe Shockwave Player | =4.0 | |
Adobe Shockwave Player | =8.5.1 | |
Adobe Shockwave Player | =11.0.0.456 | |
Adobe Shockwave Player | =6.0 | |
Adobe Shockwave Player | =10.1.0.11 | |
Adobe Shockwave Player | =11.5.0.596 | |
Adobe Shockwave Player | =1.0 | |
Adobe Shockwave Player | <=11.5.1.601 | |
Adobe Shockwave Player | =2.0 | |
Adobe Shockwave Player | =8.0 | |
Adobe Shockwave Player | =3.0 | |
Adobe Shockwave Player | =11.5.0.595 | |
Adobe Shockwave Player | =9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-3463 has been classified with a critical severity level due to its potential to allow remote code execution.
To fix CVE-2009-3463, update to the latest version of Adobe Shockwave Player, specifically version 11.5.2.602 or later.
Adobe Shockwave Player versions prior to 11.5.2.602, including earlier versions like 5.0, 4.0, and 8.5.1, are affected by CVE-2009-3463.
CVE-2009-3463 allows attackers to execute arbitrary code on vulnerable systems through crafted Shockwave content.
Disabling Adobe Shockwave Player or avoiding the use of untrusted Shockwave content can serve as temporary workarounds until the vulnerability is patched.