Adobe Flash Player copyPixelsToByteArray Integer Overflow

Discussion in 'News Aggregator' started by Packet Storm, 20 Apr 2015.

  1. Packet Storm

    Packet Storm Guest

    This Metasploit module exploits an integer overflow in Adobe Flash Player. The vulnerability occurs in the copyPixelsToByteArray method from the BitmapData object. The position field of the destination ByteArray can be used to cause an integer overflow and write contents out of the ByteArray buffer. This Metasploit module has been tested successfully on Windows 7 SP1 (32-bit), IE 8 to IE 11 and Flash 14.0.0.176, 14.0.0.145 and 14.0.0.125.

    Continue reading...
     

Share This Page

Loading...