Integer overflow in Adobe Flash Player 9.0.45.0 and earlier might allow remote attackers to execute arbitrary code via a large length value for a (1) Long string or (2) XML variable type in a crafted (a) FLV or (b) SWF file, related to an "input validation error," including a signed comparison of values that are assumed to be non-negative.
References
Link Providers
http://docs.info.apple.com/article.html?artnum=307041 cve-icon cve-icon
http://lists.apple.com/archives/security-announce/2007/Nov/msg00002.html cve-icon cve-icon
http://osvdb.org/38054 cve-icon cve-icon
http://secunia.com/advisories/26027 cve-icon cve-icon
http://secunia.com/advisories/26057 cve-icon cve-icon
http://secunia.com/advisories/26118 cve-icon cve-icon
http://secunia.com/advisories/26357 cve-icon cve-icon
http://secunia.com/advisories/27643 cve-icon cve-icon
http://secunia.com/advisories/28068 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103167-1 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-66-201506-1 cve-icon cve-icon
http://www.adobe.com/support/security/bulletins/apsb07-12.html cve-icon cve-icon
http://www.gentoo.org/security/en/glsa/glsa-200708-01.xml cve-icon cve-icon
http://www.kb.cert.org/vuls/id/730785 cve-icon cve-icon
http://www.mindedsecurity.com/labs/advisories/MSA01110707 cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2007_46_flashplayer.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/473655/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/474163/100/200/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/474248/30/5760/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/24856 cve-icon cve-icon
http://www.securityfocus.com/bid/26444 cve-icon cve-icon
http://www.securitytracker.com/id?1018359 cve-icon cve-icon
http://www.us-cert.gov/cas/techalerts/TA07-192A.html cve-icon cve-icon
http://www.us-cert.gov/cas/techalerts/TA07-319A.html cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/2497 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/3868 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/4190 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/35337 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2007-3456 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11493 cve-icon cve-icon
https://rhn.redhat.com/errata/RHSA-2007-0696.html cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2007-3456 cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2007-07-11T16:00:00

Updated: 2024-08-07T14:21:34.935Z

Reserved: 2007-06-26T00:00:00

Link: CVE-2007-3456

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2007-07-11T16:30:00.000

Modified: 2024-11-21T00:33:17.230

Link: CVE-2007-3456

cve-icon Redhat

Severity : Critical

Publid Date: 2007-07-10T00:00:00Z

Links: CVE-2007-3456 - Bugzilla