您的位置:首页 > 其它

CVE-2012-0758 Adobe Shockwave Player Parsing cupt atom heap overflow

2012-02-15 20:06 671 查看
Discover: instruder of code audit labs of vulnhunt.com

CAL: CAL-2011-0071

CVE: CVE-2012-0758


1 Affected Products

=================

adobe shockwave 11.6.3.633

adobe Shockwave 11.6.1.629 and prior


2 Vulnerability Details

=====================

When adobe shockwave player parsing a dir type file,

it takes a dword from the dir file,and then take some

Computing this computing will leding to Integer overflow,

allocate a small memory,this Cause a heap overflow.


3 Analysis

=========

asm in dirapi.dll 11.6.1.629

c code like

==================


4 Exploitable?

============

Successfully exploited this vulnerability could lead to arbitrary code execution.


5 Crash info:

===============


6 About Code Audit Labs:

=====================

Code Audit Labs secure your software,provide Professional include source

code audit and binary code audit service.

Code Audit Labs:” You create value for customer,We protect your value”
http://www.VulnHunt.com http://blog.vulnhunt.com http://t.qq.com/vulnhunt http://weibo.com/vulnhunt
内容来自用户分享和网络整理,不保证内容的准确性,如有侵权内容,可联系管理员处理 点击这里给我发消息
标签: