vendor:
Flash Player
by:
Chris Evans, Nicolas Joly, hdarwin, juan vazquez
N/A
CVSS
N/A
Integer Overflow
119
CWE
Product Name: Flash Player
Affected Version From: 14.0.0.176
Affected Version To: 14.0.0.125
Patch Exists: YES
Related CWE: CVE-2014-0556
CPE: a:adobe:flash_player:14.0.0.176
Metasploit:
https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2014-1173/, https://www.rapid7.com/db/vulnerabilities/freebsd-vid-ca44b64c-4453-11e4-9ea1-c485083ca99c/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2014-0556/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2014-0559/, https://www.rapid7.com/db/vulnerabilities/adobe-air-cve-2014-0556/, https://www.rapid7.com/db/vulnerabilities/adobe-air-cve-2014-0559/, https://www.rapid7.com/db/vulnerabilities/adobe-flash-apsb14-21-cve-2014-0559/, https://www.rapid7.com/db/vulnerabilities/adobe-flash-apsb14-21-cve-2014-0556/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2014-0556/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2014-0559/
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=77628, https://www.infosecmatter.com/nessus-plugin-library/?id=77582, https://www.infosecmatter.com/nessus-plugin-library/?id=77580, https://www.infosecmatter.com/nessus-plugin-library/?id=77578, https://www.infosecmatter.com/nessus-plugin-library/?id=77621, https://www.infosecmatter.com/nessus-plugin-library/?id=77579, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/windows/browser/adobe_flash_copy_pixels_to_byte_array, https://www.infosecmatter.com/list-of-metasploit-windows-exploits-detailed-spreadsheet/
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 SP1 (32-bit), IE 8 to IE 11
2014
Adobe Flash Player copyPixelsToByteArray Integer Overflow
This module exploits an integer overflow in Adobe Flash Player. The vulnerability occurs in the copyPixelsToByteArray method from the BitmapData object. The position field of the destination ByteArray can be used to cause an integer overflow and write contents out of the ByteArray buffer. This module has been tested successfully on Windows 7 SP1 (32-bit), IE 8 to IE 11 and Flash 14.0.0.176, 14.0.0.145 and 14.0.0.125.
Mitigation:
Update to the latest version of Adobe Flash Player