Adobe issues alert on Shockwave Player 3D graphics flaws

Article

Adobe issues alert on Shockwave Player 3D graphics flaws

Robert Westervelt, News Editor

Adobe Systems Inc. issued a critical update to its Shockwave Player repairing eight vulnerabilities that could enable attackers to infect machines with data stealing malware.

In an update issued Wednesday, Adobe said the update affects Shockwave Player 11.5.2.602 and earlier versions for Windows and Macintosh. The software maker urged users to uninstall Shockwave Player and reinstall the latest version:

    Requires Free Membership to View

    SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

Shockwave version 11.5.6.606.

The updates resolve a buffer overflow vulnerability and multiple integer overflow vulnerabilities that could lead to code execution.

Shockwave Player is one of the most widely distributed pieces of software, with more than 450 million users. Danish vulnerability clearinghouse, Secunia Research gave the Shockwave Player flaws a highly critical rating. The errors can be exploited when malicious code forces the player to render 3D graphics models. The issues were discovered by Secunia researcher Alin Rad Pop.