|
|
|
![]() |
Vulnerability Note VU#451096Oliver Debon Flash plug-in vulnerable to buffer overflow processing incorrectly formatted sound fileOverviewWhen passed an incorrectly formatted sound file, the Oliver Debon (freeware) Flash plug-in is reportedly vulnerable to a buffer overflow.I. DescriptionThe DefineSound tag in a sound file passes data to a Flash plug-in. If this tag specifies fewer samples than are actually present in the data, a buffer overflow may occur in the plug-in produced by Oliver Debon.II. ImpactThe attacker may crash browser or execute commands as the user running the Flash plug-in.III. SolutionBecause the software is unsupported and no patches are available, CERT/CC is unaware of any corrective measures.Systems Affected
References
Neal Krawetz authored the original description of the vulnerability. This document was last modified by Tim Shimeall
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||