Overview
A buffer overflow vulnerability in some versions of the Macromedia Flash Player may allow a remote attacker to execute code on a vulnerable system.
Description
The Macromedia Flash Player is a player for the Flash media format and enables frame-based animations with sound to be viewed within a web browser. Some versions of the Flash Player, specifically 7.0.53.0 and earlier, contain an array bounds checking error in the way that they handle a frame type identifier read from the Flash (SWF) file. This error can results in a heap memory access vulnerability that could allow an attacker to execute arbitrary code. A maliciously crafted SWF that exploits this vulnerability could be supplied through a web page, for example. |
Impact
A remote attacker with the ability to supply a specially crafted SWF file to a vulnerable host may be able to execute arbitrary code on that system. The attacker-supplied code would be executed with the privileges of the user opening the file. |
Solution
Apply a patch |
Workarounds
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 0 | AV:--/AC:--/Au:--/C:--/I:--/A:-- |
Temporal | 0 | E:ND/RL:ND/RC:ND |
Environmental | 0 | CDP:ND/TD:M/CR:ND/IR:ND/AR:ND |
References
- http://www.eeye.com/html/research/advisories/AD20051104.html
- http://www.sec-consult.com/228.html
- http://www.macromedia.com/devnet/security/security_zone/mpsb05-07.html
- http://secunia.com/advisories/17430/
- http://secunia.com/advisories/17481/
- http://secunia.com/advisories/17437/
- http://www.securityfocus.com/bid/15332
- http://blogs.technet.com/msrc/archive/2005/11/07/413906.aspx
- http://www.microsoft.com/technet/security/advisory/910550.mspx
- http://www.microsoft.com/technet/security/Bulletin/MS06-020.mspx
Acknowledgements
The CERT/CC credits eEye Digital Security and SEC Consult for reporting this vulnerability.
This document was written by Chad R Dougherty based on information provided by Macromedia, Inc. and eEye Digital Security.
Other Information
CVE IDs: | CVE-2005-2628 |
Severity Metric: | 13.50 |
Date Public: | 2005-11-07 |
Date First Published: | 2005-11-11 |
Date Last Updated: | 2006-05-09 18:23 UTC |
Document Revision: | 21 |