CVE Vulnerabilities

CVE-2012-1175

Published: Aug 26, 2012 | Modified: Aug 27, 2012
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Integer overflow in the GnashImage::size method in libbase/GnashImage.h in GNU Gnash 0.8.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SWF file, which triggers a heap-based buffer overflow.

Affected Software

Name Vendor Start Version End Version
Gnash Gnu 0.8.10 (including) 0.8.10 (including)
Gnash Ubuntu hardy *
Gnash Ubuntu lucid *
Gnash Ubuntu maverick *
Gnash Ubuntu natty *
Gnash Ubuntu oneiric *
Gnash Ubuntu upstream *

References