Integer overflow in Adobe Flash Player 9.0.45.0 and earlier might allow remote attackers to execute arbitrary code via a large length value for a (1) Long string or (2) XML variable type in a crafted (a) FLV or (b) SWF file, related to an "input validation error," including a signed comparison of values that are assumed to be non-negative.

Project Subscriptions

Vendors Products
Flash Player Subscribe
Rhel Extras Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
http://docs.info.apple.com/article.html?artnum=307041 cve-icon cve-icon
http://lists.apple.com/archives/security-announce/2007/Nov/msg00002.html cve-icon cve-icon
http://osvdb.org/38054 cve-icon cve-icon
http://secunia.com/advisories/26027 cve-icon cve-icon
http://secunia.com/advisories/26057 cve-icon cve-icon
http://secunia.com/advisories/26118 cve-icon cve-icon
http://secunia.com/advisories/26357 cve-icon cve-icon
http://secunia.com/advisories/27643 cve-icon cve-icon
http://secunia.com/advisories/28068 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103167-1 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-66-201506-1 cve-icon cve-icon
http://www.adobe.com/support/security/bulletins/apsb07-12.html cve-icon cve-icon
http://www.gentoo.org/security/en/glsa/glsa-200708-01.xml cve-icon cve-icon
http://www.kb.cert.org/vuls/id/730785 cve-icon cve-icon
http://www.mindedsecurity.com/labs/advisories/MSA01110707 cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2007_46_flashplayer.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/473655/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/474163/100/200/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/474248/30/5760/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/24856 cve-icon cve-icon
http://www.securityfocus.com/bid/26444 cve-icon cve-icon
http://www.securitytracker.com/id?1018359 cve-icon cve-icon
http://www.us-cert.gov/cas/techalerts/TA07-192A.html cve-icon cve-icon
http://www.us-cert.gov/cas/techalerts/TA07-319A.html cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/2497 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/3868 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/4190 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/35337 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2007-3456 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11493 cve-icon cve-icon
https://rhn.redhat.com/errata/RHSA-2007-0696.html cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2007-3456 cve-icon
History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-07T14:21:34.935Z

Reserved: 2007-06-26T00:00:00

Link: CVE-2007-3456

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2007-07-11T16:30:00.000

Modified: 2025-04-09T00:30:58.490

Link: CVE-2007-3456

cve-icon Redhat

Severity : Critical

Publid Date: 2007-07-10T00:00:00Z

Links: CVE-2007-3456 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses