CVE-2010-4188: Buffer Overflow
The dirapi.dll module in Adobe Shockwave Player before 11.5.9.620 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a Director movie with an IFWV chunk with a size field of 0, which is used in the calculation of a file offset and causes invalid data to be used as a loop counter, triggering a heap-based buffer overflow, a different vulnerability than CVE-2010-2587 and CVE-2010-2588.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4188?
CVE-2010-4188 has a critical severity rating of 9.3.
How do I fix CVE-2010-4188?
To fix CVE-2010-4188, you need to apply the available patch from Adobe for Shockwave Player.
What type of vulnerability is CVE-2010-4188?
CVE-2010-4188 is a buffer overflow vulnerability in Adobe Shockwave Player.
What can attackers achieve with CVE-2010-4188?
Attackers can execute arbitrary code or cause a denial of service due to memory corruption through CVE-2010-4188.
Which software is affected by CVE-2010-4188?
CVE-2010-4188 affects Adobe Shockwave Player versions prior to 11.5.9.620.