Integer Overflow Vulnerability in GNU Gnash Affects Remote Code Execution
CVE-2012-1175
Currently unrated
Summary
An integer overflow vulnerability exists in the GnashImage::size method within the GNU Gnash library. This flaw allows a remote attacker to exploit a crafted SWF file, potentially leading to a denial of service due to a crash of the affected application. Furthermore, this vulnerability may open the possibility for executing arbitrary code on the target system through a heap-based buffer overflow. Such exploitation poses significant risks, particularly for systems utilizing older versions of Gnash.
References
Timeline
Vulnerability published
Vulnerability Reserved