|
|
Info |
Last Modified |
| about 1 year ago |
|
|
|
|
Keywords |
166B1BCA-3F9C-11CF-8075-444553540000
|
|
Description |
A remote overflow exists in Shockwave Player ActiveX Installer. The product fails to perform boundary checks on two unspecified values when using CLSID 166B1BCA-3F9C-11CF-8075-444553540000 resulting in a stack-based buffer overflow. With a specially crafted request to a site hosting malicious shockwave content during the installation procedure, an attacker can cause arbitrary code execution resulting in a loss of integrity.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
|
|
Solution |
This flaw was fixed in the 2006-02-23 release without a change in version number.
|
|
Products |
|
Shockwave Player ActiveX Installer
 |
10.1.0.11 |
|
|
|
|
|
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|