CVE-2009-4003: Buffer Overflow
Multiple integer overflows in Adobe Shockwave Player before 11.5.6.606 allow remote attackers to execute arbitrary code via (1) an unspecified block type in a Shockwave file, leading to a heap-based buffer overflow; and might allow remote attackers to execute arbitrary code via (2) an unspecified 3D block in a Shockwave file, leading to memory corruption; or (3) a crafted 3D model in a Shockwave file, leading to heap memory corruption.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4003?
CVE-2009-4003 is rated as critical due to its potential to allow remote code execution.
How do I fix CVE-2009-4003?
The recommended fix for CVE-2009-4003 is to update Adobe Shockwave Player to the latest version that is available.
What types of attacks can CVE-2009-4003 be used for?
CVE-2009-4003 can be exploited by remote attackers to execute arbitrary code via crafted Shockwave files.
What versions of Adobe Shockwave Player are affected by CVE-2009-4003?
CVE-2009-4003 affects Adobe Shockwave Player versions up to 11.5.2.602.
What should I do if my system is using an affected version of Shockwave Player?
If using an affected version of Shockwave Player, it is important to uninstall it or update to the latest secure version immediately.