Monorail Project: project-zero Issues People Development process History Sign in
New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.
Starred by 4 users
Status: Fixed
Owner:
Email to this user bounced
Closed: Aug 2014
Cc:



Sign in to add a comment
Flash leak of uninitialized memory when rendering valid(?) 1bpp image
Reported by cevans@google.com, Jul 14 2014 Back to list
A SWF to reproduce is attached, along with source. To reproduce, host the additional resource SWF "imglossless1bpp.swf" on the same web server / directory as Lossless1bppLeak.swf

This bug is a strange one. I think the 1bpp image is reasonably well-formed and valid: it has a 2-color color table (black and white), and enough image data to fill the entire 64x64 1bpp canvas. Despite this, a multi-color image is rendered, which clearly contains some uninitialized data.

Maybe 1bpp image support is broken? I'm not really sure what's going on other than the definite observation of uninitialized memory content leaking to script.

A screenshot is attached for convenience.
 
1bpp.png
6.5 KB View Download
Lossless1bppLeak.as
1.7 KB Download
Lossless1bppLeak.swf
1.2 KB Download
imglossless1bpp.swf
1.4 KB Download
Comment 1 by cevans@google.com, Jul 14 2014
Summary: Flash leak of uninitialized memory when rendering valid(?) 1bpp image (was: Flask leak of uninitialized memory when rendering valid(?) 1bpp image)
Comment 2 by cevans@google.com, Jul 14 2014
(test)
Comment 3 by cevans@google.com, Jul 14 2014
Cc: project-...@google.com
Comment 4 by cevans@google.com, Jul 15 2014
Labels: Id-2888
Comment 5 by cevans@google.com, Aug 21 2014
Labels: CVE-2014-0543
Comment 6 by cevans@google.com, Aug 21 2014
Labels: Fixed-2014-Aug-12
Bulletin: http://helpx.adobe.com/security/products/flash-player/apsb14-18.html
Comment 7 by cevans@google.com, Aug 21 2014
Labels: -Restrict-View-Commit
Comment 8 by cevans@google.com, Aug 21 2014
Status: Fixed
Blogged about here: http://googleprojectzero.blogspot.com/2014/08/what-does-pointer-look-like-anyway.html

Marking as Fixed since the patch is available since > 1 week.
Sign in to add a comment