Critical Shockwave Install Bug Fixed

TippingPoint's Zero Day Initiative -- one of two prominent reward programs that pay researchers for information about software vulnerabilities -- warned users that a malicious Web site could hijack a user's computer if the site convinced the visitor to install Shockwave, a player used on many sites to display multi-media content.

Shockwave's ActiveX installer was at fault, said TippingPoint in its advisory.

Adobe, meanwhile, repaired the defective ActiveX installer, and said "since the vulnerability occurs in the installer, no action needs to be taken by current Macromedia Shockwave Player customers."

In other words, Shockwave users can breathe easy.

id
unit-1659132512259
type
Sponsored post

The bug's window of opportunity, however, was at least two month wide -- TippingPoint first notified Adobe of the bug on Nov. 22, 2005 -- although it's unknown how many (or if any) users might have been affected.