Buffer Overflow in Macromedia's Flash Player 6.0 ActiveX Control

A buffer overflow condition exists in Macromedia’s Flash Player 6.0 ActiveX Control.

Ken Pfeil

May 7, 2002

2 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported May 3, 2002, by eEyeDigital Security.

VERSION AFFECTED

·        Macromedia's Flash Player6.0 ActiveX Control

 

DESCRIPTION
Abuffer overflow condition exists in Macromedia's Flash Player 6.0 ActiveX Control.An attacker can use this vulnerability to execute code through email, a Website, or any other way that Microsoft Internet Explorer (IE) uses to displayHTML. eEye’s advisorygives a detailed explanation on this vulnerability.

 

DEMONSTRATION

eEyeDigital Security provided the following example as proof-of-concept:

 

VALUE="http://www.notthere8979873.com/notthere.swf?AAA[...unstated,but

fixednumber]XXXXXXXX">

 

WhereX overwrites the EIP consistently across Windows platforms.

 

VENDOR RESPONSE

Macromedia hasreleased an updated version of Shockwave Flash that addresses thisvulnerability.

 

CREDIT
Discovered by Drew Copleyand eEye Digital Security.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like