Adobe Flash BlurFilter Processing - Out-of-Bounds Memset

EDB-ID:

39219




Platform:

Multiple

Date:

2016-01-11


Become a Certified Penetration Tester

Enroll in Penetration Testing with Kali Linux , the course required to become an Offensive Security Certified Professional (OSCP)

GET CERTIFIED

Source: https://code.google.com/p/google-security-research/issues/detail?id=627

The attached swf file causes an out-of-bounds memset in BlurFilter processing. Note that Chrome aborts when processing the swf


Proof of Concept:
https://github.com/offensive-security/exploitdb-bin-sploits/raw/master/bin-sploits/39219.zip