A vulnerability has been reported in Macromedia Flash Player, which can be exploited by malicious people to compromise a user's system.
The vulnerability is caused due to an array-indexing error as the frame type identifier read from a SWF file is used as an index to reference an array of function pointers. This can be exploited via a specially crafted SWF file to use attacker-controlled memory as function pointers.
Successful exploitation allows execution of arbitrary code.
The vulnerability is reported in Flash Player version 220.127.116.11 and prior on the Windows platform and in versions prior to 18.104.22.168 on the Unix platform.
Solution: Update to Flash Player 8 (22.214.171.124) or apply Flash Player 7 update (126.96.36.199 or 188.8.131.52).
Do you have additional information related to this advisory?
Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this
information to firstname.lastname@example.org
Subject: Macromedia Flash Player Frame Type Identifier Array-Indexing Vulnerability
No posts yet
You must be logged in to post a comment.
Secunia Customer Login
Not a customer already?
Learn more about how our market leading Vulnerability Management solutions can help you manage risk and ensure compliance.