|
|
|
Vulnerability Note VU#475645
Macromedia Flash plug-in contains buffer overflow
OverviewIncorrectly formatted sound wave (SWF) files may cause a buffer overflow in the Macromedia Flash plug-in.
I. DescriptionIf the length fields in an SWF file specify fewer data than are actually present in the file, processing the file may cause a buffer overflow in the Macromedia Flash plug-in.II. ImpactThe plug-in or browser may crash. Since this buffer is only read from, this overflow is unlikely to cause execution of malicious code.III. SolutionWhile Macromedia did not produce a patch to correct this problem, it is possible that recent versions of the plug-in have corrected this problem.Systems Affected
| Vendor | Status | Date Updated |
| Macromedia | Vulnerable | 15-May-2001 |
References
http://www.securityfocus.com/bid/2162
Credit
Neal Krawetz published the intial description of this problem.
This document was last modified by Tim Shimeall
Other Information
| Date Public | 12/29/2000 |
| Date First Published | 05/17/2001 09:38:11 AM |
| Date Last Updated | 06/20/2001 |
| CERT Advisory | |
| CVE Name | CAN-2001-0166 |
| Metric | 0.49 |
| Document Revision | 12 |
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|
 |