CVE-2010-4189: Buffer Overflow
Published Feb 10, 2011
·Updated
The IML32 module in Adobe Shockwave Player before 11.5.9.620 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a Director movie containing a GIF image with a crafted global color table size value, which causes an out-of-range pointer offset.
Affected Software
42 affected components
Adobe Shockwave Player=8.5.324
Adobe Shockwave Player=5.0
Adobe Shockwave Player=4.0
Adobe Shockwave Player=8.5.1
Adobe Shockwave Player=10.1.4.020
Adobe Shockwave Player=11.5.1.601
Adobe Shockwave Player=11.0.0.456
Adobe Shockwave Player=6.0
Adobe Shockwave Player<=11.5.9.615
Adobe Shockwave Player=8.0.204
Adobe Shockwave Player=8.0.196
Adobe Shockwave Player=8.5.1.105
Adobe Shockwave Player=10.2.0.023
Adobe Shockwave Player=10.1.0.11
Adobe Shockwave Player=11.5.0.596
Adobe Shockwave Player=9.0.383
Adobe Shockwave Player=1.0
Adobe Shockwave Player=11.0.3.471
Adobe Shockwave Player=10.2.0.022
Adobe Shockwave Player=8.0.205
Adobe Shockwave Player=8.5.1.106
Adobe Shockwave Player=11.5.8.612
Adobe Shockwave Player=8.5.321
Adobe Shockwave Player=11.5.2.602
Adobe Shockwave Player=8.5.1.100
Adobe Shockwave Player=2.0
Adobe Shockwave Player=10.1.1.016
Adobe Shockwave Player=8.0
Adobe Shockwave Player=10.0.0.210
Adobe Shockwave Player=10.0.1.004
Adobe Shockwave Player=10.2.0.021
Adobe Shockwave Player=11.5.6.606
Adobe Shockwave Player=11.5.7.609
Adobe Shockwave Player=3.0
Adobe Shockwave Player=8.0.196a
Adobe Shockwave Player=10.1.0.011
Adobe Shockwave Player=9.0.432
Adobe Shockwave Player=8.5.1.103
Adobe Shockwave Player=8.5.323
Adobe Shockwave Player=8.5.325
Adobe Shockwave Player=11.5.0.595
Adobe Shockwave Player=9
Remediation
Event History
Feb 10, 2011
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-4189?
CVE-2010-4189 has a critical severity rating of 9.3.
2
How do I fix CVE-2010-4189?
To fix CVE-2010-4189, you should update Adobe Shockwave Player to version 11.5.9.620 or later.
3
What type of vulnerability is CVE-2010-4189?
CVE-2010-4189 is a buffer overflow vulnerability.
4
What attackers can do with CVE-2010-4189?
Attackers can execute arbitrary code or cause a denial of service due to memory corruption.
5
Which software is affected by CVE-2010-4189?
CVE-2010-4189 affects Adobe Shockwave Player versions prior to 11.5.9.620.