Categories: SecurityWorkspace

Adobe Warns Of Critical Shockwave Player Flaw

Adobe Systems is warning users about a critical bug in Shockwave Player that impacts both Macintosh and Windows computers.

Adobe issued an advisory about the bug on 21 October. According to Adobe, the vulnerability exists in Shockwave Player 11.5.8.612 and earlier, and could be exploited to “cause a crash and potentially allow an attacker to take control of the affected system”.

At the moment, Adobe said it is “not aware of any attacks” exploiting the bug, though “details about the vulnerability have been disclosed publicly”.

Patch on the way

A Secunia advisory about the Shockwave vulnerability said it is caused by “an array-indexing error in the handling of a certain record value in a ‘rcsL’ chunk and can be exploited to use an arbitrary dword in memory as a function pointer via a specially crafted Director file”.

Secunia advised Shockwave Player users to avoid untrusted websites, while Adobe recommended that users ensure that their machines are fully patched.

“We are currently working on determining the schedule for an update to address this vulnerability in Adobe Shockwave Player,” Adobe’s advisory said. “As always, Adobe recommends that users follow security best practices by keeping their anti-malware software and definitions up-to-date.”

In part because of their ubiquity, Adobe products have become a major target for attackers in recent years. To improve security, Adobe is introducing sandboxing technology into Adobe Reader for Windows. The update is scheduled to come in the next few weeks.

Brian Prince eWEEK USA 2014. Ziff Davis Enterprise Inc. All Rights Reserved

Recent Posts

Apple, Google Mobile Ecosystems Should Be Investigated, CMA Told

CMA receives 'provisional recommendation' from independent inquiry that Apple,Google mobile ecosystem needs investigation

1 hour ago

Australia Rejects Elon Musk Claim About Social Media Ban For Under-16s

Government minister flatly rejects Elon Musk's “unsurprising” allegation that Australian government seeks control of Internet…

4 hours ago

Northvolt Files For Bankruptcy Protection In US

Northvolt files for Chapter 11 bankruptcy protection in the United States, and CEO and co-founder…

6 hours ago

UK’s CMA Readies Cloud Sector “Behavioural” Remedies – Report

Targetting AWS, Microsoft? British competition regulator soon to announce “behavioural” remedies for cloud sector

21 hours ago

Former Policy Boss At X Nick Pickles, Joins Sam Altman Venture

Move to Elon Musk rival. Former senior executive at X joins Sam Altman's venture formerly…

23 hours ago

Bitcoin Rises Above $96,000 Amid Trump Optimism

Bitcoin price rises towards $100,000, amid investor optimism of friendlier US regulatory landscape under Donald…

1 day ago