First published: Thu May 13 2010(Updated: )
Integer signedness error in dirapi.dll in Adobe Shockwave Player before 11.5.7.609 and Adobe Director before 11.5.7.609 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .dir file that triggers an invalid read operation.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Director | <11.5.7.609 | |
Adobe Shockwave Player | <=11.5.6.606 | |
Apple macOS | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0128 is considered to have a high severity due to its potential for remote code execution and denial of service.
To fix CVE-2010-0128, users should update Adobe Shockwave Player and Adobe Director to version 11.5.7.609 or later.
CVE-2010-0128 is an integer signedness error that can lead to memory corruption.
CVE-2010-0128 affects Adobe Shockwave Player versions prior to 11.5.7.609 and Adobe Director versions prior to 11.5.7.609.
Yes, CVE-2010-0128 can be exploited remotely through crafted .dir files.