vendor:
Flash Player
by:
bilou, juan vazquez
7.5
CVSS
HIGH
Integer Overflow
190
CWE
Product Name: Flash Player
Affected Version From: 15.0.0.167
Affected Version To: 15.0.0.167
Patch Exists: YES
Related CWE: CVE-2014-0569
CPE: a:adobe:flash_player:15.0.0.167
Metasploit:
https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2014-1648/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2014-0569/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2014-0569/, https://www.rapid7.com/db/vulnerabilities/adobe-air-cve-2014-0569/, https://www.rapid7.com/db/vulnerabilities/adobe-flash-apsb14-22-cve-2014-0569/
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=78503, https://www.infosecmatter.com/nessus-plugin-library/?id=78885, https://www.infosecmatter.com/nessus-plugin-library/?id=78475, https://www.infosecmatter.com/nessus-plugin-library/?id=78440, https://www.infosecmatter.com/nessus-plugin-library/?id=78476, https://www.infosecmatter.com/nessus-plugin-library/?id=78444, https://www.infosecmatter.com/nessus-plugin-library/?id=78443, https://www.infosecmatter.com/nessus-plugin-library/?id=79404, https://www.infosecmatter.com/nessus-plugin-library/?id=124808, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/windows/browser/adobe_flash_casi32_int_overflow
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 SP1 (32-bit), IE 8 to IE 11
2014
Adobe Flash Player casi32 Integer Overflow
This module exploits an integer overflow in Adobe Flash Player. The vulnerability occurs in the casi32 method, where an integer overflow occurs if a ByteArray of length 0 is setup as domainMemory for the current application domain. This module has been tested successfully on Windows 7 SP1 (32-bit), IE 8 to IE 11 and Flash 15.0.0.167.
Mitigation:
Adobe has released a security update to address this vulnerability. Users are advised to update to the latest version of Adobe Flash Player.