|
|
|
Vulnerability Note VU#451096
Oliver Debon Flash plug-in vulnerable to buffer overflow processing incorrectly formatted sound file
OverviewWhen passed an incorrectly formatted sound file, the Oliver Debon (freeware) Flash plug-in is reportedly vulnerable to a buffer overflow.
I. DescriptionThe DefineSound tag in a sound file passes data to a Flash plug-in. If this tag specifies fewer samples than are actually present in the data, a buffer overflow may occur in the plug-in produced by Oliver Debon.II. ImpactThe attacker may crash browser or execute commands as the user running the Flash plug-in.III. SolutionBecause the software is unsupported and no patches are available, CERT/CC is unaware of any corrective measures.Systems Affected
| Vendor | Status | Date Updated |
| Macromedia | Not Vulnerable | 15-May-2001 |
References
http://www.securityfocus.com/bid/2214
Credit
Neal Krawetz authored the original description of the vulnerability.
This document was last modified by Tim Shimeall
Other Information
| Date Public | 01/05/2001 |
| Date First Published | 05/17/2001 09:36:19 AM |
| Date Last Updated | 06/20/2001 |
| CERT Advisory | |
| CVE Name | CAN-2001-0127 |
| Metric | 0.08 |
| Document Revision | 10 |
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|
 |