CVE-2005-3591
Macromedia Flash Player - Remote Code Execution via ActionDefineFunction ActionScript Call
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-3591. PoCs published by BassReFLeX.
AI-analyzed exploit summary This exploit generates a malicious SWF file targeting a buffer overflow in Macromedia Flash Plugin (flash.ocx) v7.0.19.0. The crafted file includes a DoAction tag with a long string of 'A's and other characters to trigger the overflow.
Description
Macromedia Flash plugin (1) Flash.ocx 7.0.19.0 (Windows) and earlier and (2) libflashplayer.so before 7.0.25.0 (Unix) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via parameters to the ActionDefineFunction ActionScript call in a SWF file, which causes an improper memory access condition, a different vulnerability than CVE-2005-2628.
Exploits (1)
This exploit generates a malicious SWF file targeting a buffer overflow in Macromedia Flash Plugin (flash.ocx) v7.0.19.0. The crafted file includes a DoAction tag with a long string of 'A's and other characters to trigger the overflow.