Home→Descriptions→SA47116
| Secunia ID | |
| CVE-ID | |
| Release Date |
09 May 2012 |
| Last Change |
23 Aug 2012 |
| Criticality | |
| Solution Status |
Vendor Patch |
| Software |
Adobe Flash Professional CS5 11.x |
| Where | |
| Impact |
System accessThis covers vulnerabilities where malicious people are able to gain system access and execute arbitrary code with the privileges of a local user. |
| Description |
Tielei Wang has discovered a vulnerability in Adobe Flash Professional CS5, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an integer overflow error in Flash.exe when allocating memory to process a JPG object using its image dimensions. This can be exploited to cause a heap-based buffer overflow via a specially crafted FLA file. Successful exploitation may allow execution of arbitrary code, but requires tricking a user into opening a malicious file. The vulnerability is reported in version 11.5.1.349 and prior for Windows and Macintosh (confirmed in 11.5.1.349). |
| Solution |
Update to version 11.5.2 or upgrade to Adobe Flash Professional CS6. |
| Reported by |
Tielei Wang, Georgia Tech Information Security Center via Secunia. |
| Original Advisory |
Adobe (APSB12-12): |