[NT] Macromedia Flash Player Buffer Overflow
From: SecuriTeam (support_at_securiteam.com)
Date: 11/10/05
- Previous message: SecuriTeam: "[NEWS] F-Prot/Frisk Antivirus ZIP Version Header Bypass"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: list@securiteam.com Date: 10 Nov 2005 14:57:40 +0200
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
The SecuriTeam alerts list - Free, Accurate, Independent.
Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html
- - - - - - - - -
Macromedia Flash Player Buffer Overflow
------------------------------------------------------------------------
SUMMARY
" <http://www.macromedia.com/software/flash/flashpro/> Macromedia Flash is
the industry's most advanced authoring environment for creating
interactive websites, digital experiences and mobile content."
A buffer overflow within Macromedia Flash allows attackers to execute
arbitrary code with user privileges.
DETAILS
Vulnerable Systems:
* Macromedia Flash version 6
* Macromedia Flash version 7
Immune Systems:
* Macromedia Flash version 8
The vulnerable code exists in Flash.ocx, which embodies the code
responsible for playing back SWF files. One function maintains a large,
256-element table of function pointers on the stack, and uses a frame type
identifier read from the SWF file as an index into the array, without
enforcing the array boundaries. The following disassembly
depicts the affected code:
.text:1002714F mov eax, [esi+0CA4h] ; type number
.text:10027155 mov ecx, [esi+94h] ; base of table
.text:1002715B lea eax, [ecx+eax*8] ; get element address
.text:1002715E mov ecx, [eax] ;
Although the index is not validated, its value is elsewhere restricted to
be at most 0x8000, so the attacker can cause a function pointer to be
retrieved from memory up to roughly 64KB after the base of the table on
the stack. Typically this range will include heap memory, so by planting
specific data on the heap, the attacker can very easily control the exact
value of the function pointer. Reliable exploitation using this technique
within Internet Explorer has been demonstrated by eEye Digital Security.
CVE Information:
<http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-2628>
CAN-2005-2628
ADDITIONAL INFORMATION
The information has been provided by <mailto:Advisories@eeye.com> EEYEB.
The vendor advisory ca nbe found at:
<http://www.macromedia.com/devnet/security/security_zone/mpsb05-07.html>
http://www.macromedia.com/devnet/security/security_zone/mpsb05-07.html
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Previous message: SecuriTeam: "[NEWS] F-Prot/Frisk Antivirus ZIP Version Header Bypass"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
- [EXPL] Macromedia Flash Plugin Buffer Overflow (Exploit, flash.ocx)
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... A buffer overflow vulnerability
discovered in Macromedia Flash Plugin ... In no event shall we be liable for any damages
whatsoever including direct, indirect, incidental, consequential, loss of business profits or special
damages. ... (Securiteam) - [NT] Microsoft Excel Length Parameter Parsing Buffer Overflow Vulnerability
... The following security advisory is sent to the securiteam mailing list, and
can be found at the SecuriTeam web site: http://www.securiteam.com ... * Microsoft Office XP Software
(Excel 2002) ... * Microsoft Office v. X for Mac ... (Securiteam) - [EXPL] Ipswitch WhatsUp Gold Remote Buffer Overflow Exploit
... The following security advisory is sent to the securiteam mailing list, and
can be found at the SecuriTeam web site: http://www.securiteam.com ... WhatsUp Gold Remote
Buffer Overflow Vulnerability, ... print $socket "Referer: ... (Securiteam) - [NT] Microsoft Windows NTFS Improper Handler Closing
... The following security advisory is sent to the securiteam mailing list, and
can be found at the SecuriTeam web site: http://www.securiteam.com ... from a system
shutdown, uninitialized data may be visible in files from ... (Securiteam) - [NEWS] Mac OS X Panther Screen Lock Bypass
... The following security advisory is sent to the securiteam mailing list, and
can be found at the SecuriTeam web site: http://www.securiteam.com ... tedious in actual practice
thus far. ... For the first time user actually executing anything ... (Securiteam)