New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.
Starred by 2 users
Status: Fixed
Owner:
Email to this user bounced
Closed: Feb 2015
Cc:



Sign in to add a comment
Flash: bad cast(?) in display list handling from KeenTean
Reported by cevans@google.com, Dec 3 2014 Back to list
Credit is to "Jihui Lu of KeenTeam (@K33nTeam), working with the Chromium vulnerability reward program"

Flash player 15.0.0.239 in Chrome 39 Linux x64.

This bug is hard to categorize; I'm thinking that it might be a bad cast issue after a debugging session. The impact seems to differ per-platform but be fairly deterministic per-platform. On Linux x64, I commonly see a NULL pointer dereference. Other platforms show clearer evidence of corruption; attaching a windbg log from the researcher on 32-bit Windows.

I also attach apparent variants.

This bug is subject to a 90 day disclosure deadline. If 90 days elapse
without a broadly available patch, then the bug report will automatically
become visible to the public.

 
display_list_mc6.swf
4.5 KB Download
display_list_mc1.swf
17.3 KB Download
display_list_mc8.swf
17.3 KB Download
chrome.txt
2.5 KB View Download
Comment 1 Deleted
Comment 2 Deleted
Comment 3 by cevans@google.com, Dec 4 2014
Cc: woo...@gmail.com lv.sam...@gmail.com
Comment 4 by cevans@google.com, Dec 4 2014
Labels: Id-3168
Adobe tracking as PSIRT-3168.
Comment 5 by cevans@google.com, Feb 4 2015
Labels: CVE-2015-0322
Comment 6 by cevans@google.com, Feb 6 2015
Labels: Fixed-2015-Feb-5
Status: Fixed
https://helpx.adobe.com/security/products/flash-player/apsb15-04.html
Comment 7 by cevans@google.com, Feb 12 2015
Labels: -Restrict-View-Commit
Sign in to add a comment