|
|
Flash: bad cast(?) in display list handling from KeenTean | |||||
| Reported by cevans@google.com, Dec 3 2014 | Back to list | |||||
Credit is to "Jihui Lu of KeenTeam (@K33nTeam), working with the Chromium vulnerability reward program" Flash player 15.0.0.239 in Chrome 39 Linux x64. This bug is hard to categorize; I'm thinking that it might be a bad cast issue after a debugging session. The impact seems to differ per-platform but be fairly deterministic per-platform. On Linux x64, I commonly see a NULL pointer dereference. Other platforms show clearer evidence of corruption; attaching a windbg log from the researcher on 32-bit Windows. I also attach apparent variants. This bug is subject to a 90 day disclosure deadline. If 90 days elapse without a broadly available patch, then the bug report will automatically become visible to the public.
Comment 1
Deleted
,
Dec 4 2014
,
Dec 4 2014
Adobe tracking as PSIRT-3168.
,
Feb 4 2015
,
Feb 6 2015
https://helpx.adobe.com/security/products/flash-player/apsb15-04.html
,
Feb 12 2015
,
May 6 2015
Reward tracking: https://code.google.com/p/chromium/issues/detail?id=470749 |
||||||
| ► Sign in to add a comment | ||||||