CVE-2010-1292: Buffer Overflow
The implementation of pami RIFF chunk parsing in Adobe Shockwave Player before 11.5.7.609 does not validate a certain value from a file before using it in file-pointer calculations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .dir (aka Director) file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1292?
CVE-2010-1292 is classified with a high severity level as it allows remote attackers to execute arbitrary code or cause memory corruption.
How do I fix CVE-2010-1292?
To fix CVE-2010-1292, upgrade Adobe Shockwave Player to version 11.5.7.609 or later.
What versions of Adobe Shockwave Player are affected by CVE-2010-1292?
CVE-2010-1292 affects all versions of Adobe Shockwave Player before 11.5.7.609.
Can CVE-2010-1292 lead to denial of service?
Yes, CVE-2010-1292 can lead to denial of service due to memory corruption.
What is the type of vulnerability identified in CVE-2010-1292?
CVE-2010-1292 is a vulnerability related to improper validation in the parsing of pami RIFF chunks.