|
|
Flash memory corruption in Actionscript 2 Array.join | ||||||
| Project Member Reported by ianbeer@google.com, Aug 19 2014 | Back to list | ||||||
There's a signedness issue when calling the join method on an Actionscript 2 Array containing long strings. The attached PoC crashes the latest Chrome Canary on Mac flash ppapi process inside memmove. build the PoC like this: mtasc -swf ArrToStr.swf -version 8 -main -header 800:600:25 ArrToStr.as X.as
Project Member
Comment 1
by
ianbeer@google.com,
Aug 19 2014
,
Aug 19 2014
,
Sep 23 2014
,
Oct 10 2014
,
Nov 8 2014
Making report public. This was fixed ages ago in http://helpx.adobe.com/security/products/flash-player/apsb14-22.html
,
Jan 13 2015
|
|||||||
| ► Sign in to add a comment | |||||||