|
|
Flash: memory corruption with ShaderJob width and height TOCTOU condition | ||||
| Reported by cevans@google.com, Apr 3 2015 | Back to list | ||||
The attached PoC, with source, should illustrate. The condition of interest seems to be setting off an asynchronous ShaderJob and then modifying the width / height before the shader threads complete. It looks like a TOCTOU. This bug is subject to a 90 day disclosure deadline. If 90 days elapse without a broadly available patch, then the bug report will automatically become visible to the public.
Comment 1
by
cevans@google.com,
Apr 6 2015
,
May 7 2015
,
May 12 2015
https://helpx.adobe.com/security/products/flash-player/apsb15-09.html
,
Jun 26 2015
|
|||||
| ► Sign in to add a comment | |||||