Adobe Flash Player Multimedia File Remote Buffer Overflow Vulnerability
BID:28695
Info
Adobe Flash Player Multimedia File Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 28695 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-0071 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 08 2008 12:00AM |
| Updated: | May 07 2015 06:19PM |
| Credit: | Mark Dowd of the ISS X-Force, wushi of team509 |
| Vulnerable: |
Turbolinux wizpy 0 Turbolinux FUJI 0 SuSE SUSE Linux Enterprise Desktop 10 SP1 SuSE openSUSE 10.3 Sun Solaris 10_x86 Sun Solaris 10_sparc Sun OpenSolaris build snv_88 S.u.S.E. openSUSE 10.2 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux 10.1 x86-64 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc RedHat Enterprise Linux Extras 4 RedHat Enterprise Linux Extras 3 Red Hat Enterprise Linux Supplementary 5 server Red Hat Enterprise Linux Desktop Supplementary 5 client Nortel Networks Self-Service Peri Workstation 0 Nortel Networks Self-Service Peri Application 0 Nortel Networks Self-Service MPS 1000 0 Nortel Networks Self-Service Media Processing Server 0 Nortel Networks Self-Service - CCSS7 0 Nortel Networks Self-Service 0 Gentoo Linux Apple Mac OS X Server 10.5.2 Apple Mac OS X Server 10.5.1 Apple Mac OS X Server 10.4.11 Apple Mac OS X Server 10.5 Apple Mac OS X 10.5.2 Apple Mac OS X 10.5.1 Apple Mac OS X 10.4.11 Apple Mac OS X 10.5 Adobe Flex 3.0 Adobe Flash Professional 8 Adobe Flash Player Plugin 9.0.31 .0 Adobe Flash Player Plugin 9.0.28 .0 Adobe Flash Player Plugin 9.0.20 .0 Adobe Flash Player Plugin 9.0.16 Adobe Flash Player Plugin 8.0 Adobe Flash Player Plugin 9.0.18d60 Adobe Flash Player 9.0.48.0 Adobe Flash Player 9.0.47.0 Adobe Flash Player 9.0.45.0 Adobe Flash Player 9.0.31.0 Adobe Flash Player 9.0.28.0 Adobe Flash Player 9.0.115.0 Adobe Flash Player 9 Adobe Flash Player 8.0.35.0 Adobe Flash Player 8.0.34.0 Adobe Flash CS3 Professional 0 Adobe Flash Basic 8 Adobe AIR 1.0 |
| Not Vulnerable: |
Adobe Flash Professional 8 8.0.42.0 Adobe Flash Player Plugin 9.0.124.0 Adobe Flash Player 9.0.124 .0 Adobe Flash Basic 8.0.42.0 Adobe AIR 1.01 |
Discussion
Adobe Flash Player Multimedia File Remote Buffer Overflow Vulnerability
Adobe Flash Player is prone to a remote buffer-overflow vulnerability when handling multimedia files with certain tags.
An attacker may exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
Adobe Flash Player 9.0.115.0 and earlier versions are affected.
NOTE: This issue has been fixed in all versions of Adobe Flash Player 9.0.124.0.
Initial investigations suggested that the vulnerability had not been patched in the standalone Adobe Flash Player version 9.0.124.0 for Linux and the standalone Adobe Flash Player version 9.0.124.0 with debug capabilities for Microsoft Windows. The observed behavior that led to this initial conclusion has since been confirmed by Adobe as intended by design.
Adobe Flash Player is prone to a remote buffer-overflow vulnerability when handling multimedia files with certain tags.
An attacker may exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
Adobe Flash Player 9.0.115.0 and earlier versions are affected.
NOTE: This issue has been fixed in all versions of Adobe Flash Player 9.0.124.0.
Initial investigations suggested that the vulnerability had not been patched in the standalone Adobe Flash Player version 9.0.124.0 for Linux and the standalone Adobe Flash Player version 9.0.124.0 with debug capabilities for Microsoft Windows. The observed behavior that led to this initial conclusion has since been confirmed by Adobe as intended by design.
Exploit / POC
Adobe Flash Player Multimedia File Remote Buffer Overflow Vulnerability
"Application-Specific Attacks: Leveraging the ActionScript Virtual Machine", a paper by Mark Dowd of X-Force IBM ISS, describes in detail the techniques required to exploit this issue and serves as a proof of concept. Please see the references for more information.
An exploit and a proof of concept are available for members of Immunity's CANVAS Early Update Program:
https://www.immunityinc.com/downloads/immpartners/flash_duke.tgz
https://www.immunityinc.com/downloads/immpartners/CVE-2007-0071.tgz
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Symantec has observed that this issue is being actively exploited in the wild.
UPDATE: Continued investigation reveals that this issue is fairly widespread. Malicious code is being injected into other third-party domains (approximately 20,000 web pages), most likely through SQL-injection attacks. The code then redirects users to sites hosting malicious Flash files exploiting this issue.
"Application-Specific Attacks: Leveraging the ActionScript Virtual Machine", a paper by Mark Dowd of X-Force IBM ISS, describes in detail the techniques required to exploit this issue and serves as a proof of concept. Please see the references for more information.
An exploit and a proof of concept are available for members of Immunity's CANVAS Early Update Program:
https://www.immunityinc.com/downloads/immpartners/flash_duke.tgz
https://www.immunityinc.com/downloads/immpartners/CVE-2007-0071.tgz
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Symantec has observed that this issue is being actively exploited in the wild.
UPDATE: Continued investigation reveals that this issue is fairly widespread. Malicious code is being injected into other third-party domains (approximately 20,000 web pages), most likely through SQL-injection attacks. The code then redirects users to sites hosting malicious Flash files exploiting this issue.
Solution / Fix
Adobe Flash Player Multimedia File Remote Buffer Overflow Vulnerability
Solution:
The vendor released Flash Player 9.0.124.0 to address this issue. Please see the references for more information.
Apple Mac OS X Server 10.5
Apple Mac OS X 10.5
Apple Mac OS X Server 10.4.11
Apple Mac OS X 10.4.11
Apple Mac OS X 10.5.1
Apple Mac OS X Server 10.5.1
Apple Mac OS X 10.5.2
Apple Mac OS X Server 10.5.2
Solution:
The vendor released Flash Player 9.0.124.0 to address this issue. Please see the references for more information.
Apple Mac OS X Server 10.5
-
Apple Security Update 2008-003 Server (PPC)
http://www.apple.com/support/downloads/securityupdate2008003serverppc. html -
Apple Security Update 2008-003 Server (Universal)
http://www.apple.com/support/downloads/securityupdate2008003serveruniv ersal.html
Apple Mac OS X 10.5
-
Apple Security Update 2008-003 (Intel)
http://www.apple.com/support/downloads/securityupdate2008003intel.html -
Apple Security Update 2008-003 (PPC)
http://www.apple.com/support/downloads/securityupdate2008003ppc.html
Apple Mac OS X Server 10.4.11
-
Apple Security Update 2008-003 Server (PPC)
http://www.apple.com/support/downloads/securityupdate2008003serverppc. html -
Apple Security Update 2008-003 Server (Universal)
http://www.apple.com/support/downloads/securityupdate2008003serveruniv ersal.html
Apple Mac OS X 10.4.11
-
Apple Security Update 2008-003 (Intel)
http://www.apple.com/support/downloads/securityupdate2008003intel.html -
Apple Security Update 2008-003 (PPC)
http://www.apple.com/support/downloads/securityupdate2008003ppc.html
Apple Mac OS X 10.5.1
-
Apple Security Update 2008-003 (Intel)
http://www.apple.com/support/downloads/securityupdate2008003intel.html -
Apple Security Update 2008-003 (PPC)
http://www.apple.com/support/downloads/securityupdate2008003ppc.html
Apple Mac OS X Server 10.5.1
-
Apple Security Update 2008-003 Server (PPC)
http://www.apple.com/support/downloads/securityupdate2008003serverppc. html -
Apple Security Update 2008-003 Server (Universal)
http://www.apple.com/support/downloads/securityupdate2008003serveruniv ersal.html
Apple Mac OS X 10.5.2
-
Apple Security Update 2008-003 (Intel)
http://www.apple.com/support/downloads/securityupdate2008003intel.html -
Apple Security Update 2008-003 (PPC)
http://www.apple.com/support/downloads/securityupdate2008003ppc.html
Apple Mac OS X Server 10.5.2
-
Apple Security Update 2008-003 Server (PPC)
http://www.apple.com/support/downloads/securityupdate2008003serverppc. html -
Apple Security Update 2008-003 Server (Universal)
http://www.apple.com/support/downloads/securityupdate2008003serveruniv ersal.html
References
Adobe Flash Player Multimedia File Remote Buffer Overflow Vulnerability
References:
References:
- Adobe Flash Homepage (Adobe)
- Adobe Homepage (Adobe)
- Application-Specific Attacks:Leveraging the ActionScript Virtual Machine (Mark Dowd of X-Force IBM ISS)
- FrequencyX Blog: Flash (X-Force IBM ISS)
- Install Adobe Flash Player (Adobe)
- Malware Attack Exploiting Flash Zero Day Vulnerability (Dancho Danchev)
- Potential Flash Player issue (Adobe)
- APSB08-11 Flash Player update available to address security vulnerabilities (Adobe)
- Nortel Response to Sun Alert 238305 - Multiple Security Vulnerabilities in Flash (Nortel Networks)
- RHSA-2008:0221-3: Critical: flash-plugin security update (Red Hat)
- Solution 238305: Multiple Security Vulnerabilities in Flash Player for Solaris (Sun Microsystems)
- VU#395473 - Adobe Flash player code execution vulnerability (US-CERT)
- Vulnerability Note VU#159523 Adobe Flash Player integer overflow vulnerability (US-CERT)
- ZDI-08-032: Adobe Flash DefineSceneAndFrameLabelData Parsing Memory Corruption V (Zero Day Initiative)