Adobe Flash Player Out of Bounds Memory Indexing Vulnerability
2 Jul. 2010
Summary
Remote exploitation of an array indexing vulnerability in Adobe Systems Inc.'s Flash Player could allow an attacker to execute arbitrary code with the privileges of the current user.
Vulnerable Systems:
* Adobe Flash Player version 10.0.22.87
* Adobe Flash Player version 10.0.45.2 and prior
* Adobe AIR version 1.5.3.9130 and prior
During the processing of certain types of Adobe Flash code, a certain function may be tricked into accepting an overly large index argument. The index argument may reference a memory location outside the bounds of memory allocated for an array object. Arbitrary code execution can occur when an index is calculated to point to a sensitive memory location, and the memory location is overwritten with specially crafted values.
Workaround:
A Internet Explorer plugin is available to temporarily block and unblock Flash content using a single click. Only trusted sites should be unblocked when using this plugin.
More information is available at http://flash.melameth.com.