what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Adobe FMS 3.5.6 / 4.0.2 Denial Of Service

Adobe FMS 3.5.6 / 4.0.2 Denial Of Service
Posted Oct 13, 2011
Authored by Knud | Site nsense.fi

nSense Vulnerability Research Security Advisory - Adobe Flash Media Servers (FMS) versions 3.5.6 and below and 4.0.2 and below suffer from a denial of service vulnerability.

tags | advisory, denial of service
advisories | CVE-2011-2132
SHA-256 | 7e626c6eab58c87b89031859246abce098102e446fc040aa85a6e11b9a71fbc7

Adobe FMS 3.5.6 / 4.0.2 Denial Of Service

Change Mirror Download
      nSense Vulnerability Research Security Advisory NSENSE-2011-003
---------------------------------------------------------------

Affected Vendor: Adobe
Affected Product: Adobe Flash media server
Platform: Linux / Windows
Impact: Remote Denial of Service
Vendor response: Patch, APSB11-20
CVE: CVE-2011-2132
Credit: Knud / nSense

Technical details
---------------------------------------------------------------
It is possible to cause a Denial of Service in Adobes Flash
Media Server (FMS) in versions <= 3.5.6 and <=4.0.2, caused
by a null-pointer dereference. A brief crash analysis follows:
Program received signal SIGSEGV, Segmentation fault.
[Switching to Thread 0xb5735b70 (LWP 6185)]
0x08233636 in strlwr ()
(gdb) x/i $pc
0x8233636 <_Z6strlwrPc+22>: movzx eax,BYTE PTR [esi]
(gdb) i r eax esi
eax 0x84cc237 139248183
esi 0x0 0

The condition may be replicated using a web server by accessing
the following URL: http://<target>:1111/?%


Timeline:
20110522 Contacted vendor
20110523 Vendor acknowledges receipt of information
20110523 Vendor creates ticket,# 984
20110604 nSense requests preliminary timeline
20110604 Vendor responds, issue reproduced & being fixed
20110727 Vendor responds, CVE assigned, patch 20110809

Solution
Install the vendor supplied patch:
http://www.adobe.com/support/flashmediaserver/downloads_updaters.html

Links:
http://www.nsense.fi http://www.nsense.dk



$$s$$$$s. ,s$$$$s ,S$$$$$s. $$s$$$$s. ,s$$$$s ,S$$$$$s.
$$$ `$$$ ($$( $$$ `$$$ $$$ `$$$ ($$( $$$ `$$$
$$$ $$$ `^$$s. $$$$$$$$$ $$$ $$$ `^$$s. $$$$$$$$$
$$$ $$$ )$$) $$$ $$$ $$$ )$$) $$$
$$$ $$$ ^$$$$$$7 `7$$$$$P $$$ $$$ ^$$$$$$7 `7$$$$$P

D r i v e n b y t h e c h a l l e n g e _

Login or Register to add favorites

File Archive:

October 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Oct 1st
    39 Files
  • 2
    Oct 2nd
    23 Files
  • 3
    Oct 3rd
    18 Files
  • 4
    Oct 4th
    20 Files
  • 5
    Oct 5th
    0 Files
  • 6
    Oct 6th
    0 Files
  • 7
    Oct 7th
    17 Files
  • 8
    Oct 8th
    66 Files
  • 9
    Oct 9th
    25 Files
  • 10
    Oct 10th
    20 Files
  • 11
    Oct 11th
    21 Files
  • 12
    Oct 12th
    0 Files
  • 13
    Oct 13th
    0 Files
  • 14
    Oct 14th
    14 Files
  • 15
    Oct 15th
    49 Files
  • 16
    Oct 16th
    28 Files
  • 17
    Oct 17th
    23 Files
  • 18
    Oct 18th
    10 Files
  • 19
    Oct 19th
    0 Files
  • 20
    Oct 20th
    0 Files
  • 21
    Oct 21st
    0 Files
  • 22
    Oct 22nd
    0 Files
  • 23
    Oct 23rd
    0 Files
  • 24
    Oct 24th
    0 Files
  • 25
    Oct 25th
    0 Files
  • 26
    Oct 26th
    0 Files
  • 27
    Oct 27th
    0 Files
  • 28
    Oct 28th
    0 Files
  • 29
    Oct 29th
    0 Files
  • 30
    Oct 30th
    0 Files
  • 31
    Oct 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close