v4ng3l1s / google-security-research

Automatically exported from code.google.com/p/google-security-research
0 stars 0 forks source link

Flash: bad cast(?) in display list handling from KeenTean #209

Closed GoogleCodeExporter closed 9 years ago

GoogleCodeExporter commented 9 years ago
Credit is to "Jihui Lu of KeenTeam (@K33nTeam), working with the Chromium 
vulnerability reward program"

Flash player 15.0.0.239 in Chrome 39 Linux x64.

This bug is hard to categorize; I'm thinking that it might be a bad cast issue 
after a debugging session. The impact seems to differ per-platform but be 
fairly deterministic per-platform. On Linux x64, I commonly see a NULL pointer 
dereference. Other platforms show clearer evidence of corruption; attaching a 
windbg log from the researcher on 32-bit Windows.

I also attach apparent variants.

This bug is subject to a 90 day disclosure deadline. If 90 days elapse
without a broadly available patch, then the bug report will automatically
become visible to the public.

Original issue reported on code.google.com by cev...@google.com on 3 Dec 2014 at 9:03

Attachments:

GoogleCodeExporter commented 9 years ago
[deleted comment]
GoogleCodeExporter commented 9 years ago
[deleted comment]
GoogleCodeExporter commented 9 years ago

Original comment by cev...@google.com on 4 Dec 2014 at 3:42

GoogleCodeExporter commented 9 years ago
Adobe tracking as PSIRT-3168.

Original comment by cev...@google.com on 4 Dec 2014 at 3:45

GoogleCodeExporter commented 9 years ago

Original comment by cev...@google.com on 4 Feb 2015 at 7:09

GoogleCodeExporter commented 9 years ago
https://helpx.adobe.com/security/products/flash-player/apsb15-04.html

Original comment by cev...@google.com on 6 Feb 2015 at 3:14

GoogleCodeExporter commented 9 years ago

Original comment by cev...@google.com on 12 Feb 2015 at 8:11