LWN.net Logo

gnash: heap-based buffer overflow

Package(s):gnash CVE #(s):CVE-2012-1175
Created:March 20, 2012 Updated:March 27, 2012
Description: From the Debian advisory:

Tielei Wang from Georgia Tech Information Security Center discovered a vulnerability in GNU Gnash which is caused due to an integer overflow error and can be exploited to cause a heap-based buffer overflow by tricking a user into opening a specially crafted SWF file.

Alerts:
Debian DSA-2435-1 2012-03-20
Fedora FEDORA-2012-4070 2012-03-26
Fedora FEDORA-2012-4032 2012-03-26
openSUSE openSUSE-SU-2012:0415-1 2012-03-27
Gentoo 201207-08 2012-07-09

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds