|
|
| |
| Unity 3D Web Player suffers from denial of service vulnerability. |
| |
Credit:
The information has been provided by Luigi Auriemma.
|
| |
Vulnerable Systems:
* Unity 3D Web Player <= 3.2.0.61061
Heap corruption caused by a negative 32bit size value which allows to execute malicious code.
The provided proof-of-concept is not optimized but should show a write4 and, (tested on Firefox) EIP pointing to an invalid memory zone.
The Code
http://aluigi.org/poc/unity3d_1.zip
http://www.exploit-db.com/sploits/18512.zip
Disclosure Timeline:
Published: 2012-02-22
|
|
blog comments powered by
|