Title: Macromedia Flash Player Flash.ocx Unspecified Function Arbitrary Code Execution
Info
Disclosure
Nov 02, 2005
Discovery
Unknown
Dates
Exploit
Unknown
Solution
Nov 02, 2005
Description
Flash.ocx, part of Macromedia Flash Player, fails to perform proper validation of the frame type identifier from SWF files. The frame type identifier is used as an index into an array of function pointers. With a specially crafted SWF file, a remote attacker can cause arbitrary code execution, resulting in a loss of integrity.
Classification
Location:
Remote / Network Access
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Disclosure:
OSVDB Verified
Solution
Upgrade to Flash Player 8 (8.0.22.0) or Flash Player 7 update 7.0.60.0 or higher, as they have been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.