Security weakness fixed in a new version of Adobe Shockwave Player - SSO-AL2009-034
30 July 2009
Software and platforms affected
The following software is affected
Adobe Shockwave Player prior to verion 11.5.0.601
for the following operating system platforms:
Windows
What is the problem?
There are bugs in the Adobe Shockwave Player software (for versions prior to version 11.5.0.601) which, if not fixed, could result in your computer being attacked by criminals. Your personal and/or business information may be accessed for fraudulent or illegal purposes (eg, identity theft).
This software is installed on your computer as a browser plug-in to display media content found on many popular web sites, including some animation and video formats. Be aware that if you use several browsers, there could be several versions of Adobe Shockwave Player on your computer. Also see the "What we recommend you do" section of this alert.
What we recommend you do
Adobe has released a new version of Shockwave Player (11.5.0.601) which fixes the security bugs. We recommend you install the latest version by visiting the following URL with your web browser:
http://get.adobe.com/shockwave/
Be aware that if you use several different web browsers, you will have to visit the URL mentioned above with every browser installed on your computer.
Where you can find more information
Adobe Product Security Incident Response Team (PSIRT):
Security Update available for Shockwave Player:
http://www.adobe.com/support/security/bulletins/apsb09-11.html
Disclaimer
This Alert has been prepared by AusCERT for the Department of Broadband, Communications and the Digital Economy. The information is intended for used by home users and small to medium sized businesses and is general information only and not intended as advice and was accurate and up to date at the time of publishing. The material and information in this Alert is not adapted to any particular person's circumstances and therefore cannot be relied upon to be of assistance in any particular case. In any important matter, you should seek professional advice relevant to your own circumstances. The Commonwealth, AusCERT, and all other persons associated with this Alert accept no responsibility or liability for information either included or referred to in the Alert. No responsibility or liability is accepted for any damage, loss or expense incurred as a result of the information contained in the Alert, whether by way of negligence or otherwise. The listing of a person or organisation in any part of this site or Alert does not imply any form of endorsement by the Commonwealth of the products or services provided by that person or organisation. Similarly, links to other web sites have been inserted for your convenience and do not constitute endorsement of material at those sites, or any associated organisation, product or service. Please note that material in this Alert, as the case may be, includes views or recommendations of third parties, which do not necessarily reflect the views of the Commonwealth, or indicate its commitment to particular course of action. Material on this site or in this Alert may also include information provided by third parties. The Commonwealth cannot verify the accuracy of information that has been provided by third parties.




