Integer Overflow Vulnerability in GNU Gnash Affects Remote Code Execution
CVE-2012-1175

Currently unrated

Key Information:

Vendor
Gnu
Status
Vendor
CVE Published:
26 August 2012

Summary

An integer overflow vulnerability exists in the GnashImage::size method within the GNU Gnash library. This flaw allows a remote attacker to exploit a crafted SWF file, potentially leading to a denial of service due to a crash of the affected application. Furthermore, this vulnerability may open the possibility for executing arbitrary code on the target system through a heap-based buffer overflow. Such exploitation poses significant risks, particularly for systems utilizing older versions of Gnash.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.