CVE-2007-2500
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
server/parser/sprite_definition.cpp in GNU Gnash (aka GNU Flash Player) 0.7.2 allows remote attackers to execute arbitrary code via a large number of SHOWFRAME elements within a DEFINESPRITE element, which triggers memory corruption and enables the attacker to call free with an arbitrary address, probably resultant from a buffer overflow.
server/parser/sprite_definition.cpp de GNU Gnash (también conocido como GNU Flash Player) 0.7.2 permite a atacantes remotos ejecutar código de su elección mediante un número grande de elementos SHOWFRAME dentro de un elemento DEFINESPRITE, lo cual dispara corrupción de memoria y habilita al atacante a invocar liberación de memoria de direcciones de su elección, probablemente como resultado de un desbordamiento de búfer.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-05-03 CVE Reserved
- 2007-05-04 CVE Published
- 2024-01-28 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://osvdb.org/37273 | Vdb Entry | |
http://savannah.gnu.org/bugs/?19774 | X_refsource_misc | |
http://secunia.com/advisories/25787 | Third Party Advisory | |
http://www.securityfocus.com/bid/23765 | Vdb Entry | |
http://www.securitytracker.com/id?1018041 | Vdb Entry | |
http://www.vupen.com/english/advisories/2007/1688 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/34148 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.novell.com/linux/security/advisories/2007_13_sr.html | 2017-07-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Gnu Search vendor "Gnu" | Flash Player Search vendor "Gnu" for product "Flash Player" | <= 0.7.2 Search vendor "Gnu" for product "Flash Player" and version " <= 0.7.2" | - |
Affected
|