server/parser/sprite_definition.cpp in GNU Gnash (aka GNU Flash Player) 0.7.2 allows remote attackers to execute arbitrary code via a large number of SHOWFRAME elements within a DEFINESPRITE element, which triggers memory corruption and enables the attacker to call free with an arbitrary address, probably resultant from a buffer overflow.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T13:42:33.457Z
Reserved: 2007-05-03T00:00:00
Link: CVE-2007-2500
No data.
Status : Deferred
Published: 2007-05-04T00:19:00.000
Modified: 2025-04-09T00:30:58.490
Link: CVE-2007-2500
No data.
OpenCVE Enrichment
No data.
Weaknesses