Release date: January 19, 2010
Vulnerability identifier: APSB10-03
CVE number: CVE-2009-4002, CVE-2009-4003
Platform: Windows and Macintosh
Critical vulnerabilities have been identified in Adobe Shockwave Player 11.5.2.602 and earlier versions, on the Windows and Macintosh operating systems. The vulnerabilities could allow an attacker, who successfully exploits the vulnerabilities, to run malicious code on the affected system. Adobe has provided a solution for the reported vulnerabilities. It is recommended that users update their installations to the latest version using the instructions provided below.
Shockwave Player 11.5.2.602 and earlier versions for Windows and Macintosh
Adobe recommends Shockwave Player users uninstall Shockwave version 11.5.2.602 and earlier on their systems, restart their systems, and install Shockwave version 11.5.6.606, available here: http://get.adobe.com/shockwave/.
Adobe categorizes this as a critical update and recommends that users apply the update for their product installations.
Critical vulnerabilities have been identified in Adobe Shockwave Player 11.5.2.602 and earlier versions, on the Windows and Macintosh operating systems. The vulnerabilities could allow an attacker, who successfully exploits the vulnerabilities, to run malicious code on the affected system. Adobe has provided a solution for the reported vulnerabilities. It is recommended that users update their installations to the latest version using the instructions provided above.
This update resolves a buffer overflow vulnerability that could potentially lead to code execution (CVE-2009-4002).
This update resolves multiple integer overflow vulnerabilities that could potentially lead to code execution (CVE-2009-4003).
Adobe would like to thank the following individuals and organizations for reporting the relevant issues and for working with Adobe to help protect our customers: