Adobe Flash Vulnerable To New Exploit Class[->] 2008-04-16 00:00 spikedLemur
Submitted
by
spikedLemur
on Wednesday April 16, @12:00AM
spikedLemur writes "Security guru Mark Dowd of TAoSSA has figured out how to turn a class of DoS bugs into a code execution attack. He wrote a detailed PDF explaining how he used a NULL pointer dereference in Flash to create a 100% reliable cross-browser/platform exploit. The guys at Matasano have already discussed the technique in two detailed writeups, which I highly recommend for the casual reader. Since the root problem is an ignored malloc failure (a very common mistake) we can expect to see this bug class popping up in lot of software in the near future. You might also want to make sure your Flash installation has the most current patch, since almost everybody is vulnerable to this one."
http://www.matasano.com/log/1032/this-new-vulnerability-dowds-inhuman-flash-exploit/
http://www.matasano.com/log/1032/this-new-vulnerability-dowds-inhuman-flash-exploit/

