CVE-2007-2500

Publication date 4 May 2007

Last updated 24 July 2024


Ubuntu priority

server/parser/sprite_definition.cpp in GNU Gnash (aka GNU Flash Player) 0.7.2 allows remote attackers to execute arbitrary code via a large number of SHOWFRAME elements within a DEFINESPRITE element, which triggers memory corruption and enables the attacker to call free with an arbitrary address, probably resultant from a buffer overflow.

Status

Package Ubuntu Release Status
gnash 7.10 gutsy
Fixed 0.7.2+cvs20070518.1557-1
7.04 feisty
Fixed 0.7.2-1ubuntu0.1
6.10 edgy Not in release
6.06 LTS dapper Not in release