Macromedia Flash ActiveX Component Buffer Overflow Vulnerability
BID:4664
Info
Macromedia Flash ActiveX Component Buffer Overflow Vulnerability
| Bugtraq ID: | 4664 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 02 2002 12:00AM |
| Updated: | May 02 2002 12:00AM |
| Credit: | Credited to Drew Copley. |
| Vulnerable: |
Macromedia Flash 6.0 |
| Not Vulnerable: |
Macromedia Flash 6.0.29 .0 |
Discussion
Macromedia Flash ActiveX Component Buffer Overflow Vulnerability
Macromedia produces an ActiveX plugin version of the Flash Player, designed to work with Microsoft Internet Explorer. A vulnerability has been reported in some versions of this component.
A buffer overflow exists in the parameter handling of this component. If an oversized parameter is including in the URI passed to the ActiveX component, process memory is corrupted. Exploitation of this vulnerability may result in arbitrary code execution when a malicious web page is viewed. It may be possible to exploit this vulnerability through HTML formatted email, this has not however been confirmed.
Macromedia produces an ActiveX plugin version of the Flash Player, designed to work with Microsoft Internet Explorer. A vulnerability has been reported in some versions of this component.
A buffer overflow exists in the parameter handling of this component. If an oversized parameter is including in the URI passed to the ActiveX component, process memory is corrupted. Exploitation of this vulnerability may result in arbitrary code execution when a malicious web page is viewed. It may be possible to exploit this vulnerability through HTML formatted email, this has not however been confirmed.
Exploit / POC
Macromedia Flash ActiveX Component Buffer Overflow Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Macromedia Flash ActiveX Component Buffer Overflow Vulnerability
Solution:
An updated version is available:
Macromedia Flash 6.0
Solution:
An updated version is available:
Macromedia Flash 6.0
-
Macromedia Flash Player ActiveX Control 6.0.29.0
http://www.macromedia.com/shockwave/download/index.cgi?P1_Prod_Version =ShockwaveFlash
References
Macromedia Flash ActiveX Component Buffer Overflow Vulnerability
References:
References:
- Macromedia Flash Player Download Center (Macromedia)