what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Adobe Flash Player 10.0 Denial Of Service

Adobe Flash Player 10.0 Denial Of Service
Posted May 21, 2010
Authored by Kil13r | Site kil13r.info

Adobe Flash Player 10.0 allows local users to cause a denial of service (memory consumption and system crash).

tags | advisory, denial of service, local
SHA-256 | 6e2c47492df2b9bb6aec5b94b53dc412e6f5033b54ae426ce87658e1919aa698

Adobe Flash Player 10.0 Denial Of Service

Change Mirror Download
Title:
[Kil13r-SA-20100513] Adobe Flash Player 10.0 Denial Of Service Vulnerability

Author:
Kil13r - http://www.kil13r.info/

Local / Remote:
Local

Timeline:
2008/10/22 - Discover
2009/07/19 - Vendor notification
2009/07/21 - Vendor response
2009/07/25 - Contact vendor
2009/07/28 - Vendor response (Unable to reproduce)
2009/07/28 - Contact vendor
2009/11/18 - Contact vendor (Vendor prerelease 10.1, PoC doesn't work anymore)
2009/11/19 - Vendor response (Still unable to reproduce the issue in 10.0)
2009/11/19 - Contact vendor (Send video demo)
2009/11/26 - Vendor response
2010/05/13 - Release
2010/05/18 - Resend to bugtraq
2010/05/18 - Bugtraq response (Send some more technical information)
2010/05/19 - Resend to bugtraq (Add more technical information)

Affected version:
Adobe Flash Player 10.0

Not affected version:
Adobe Flash Player 10.1+

Description:
Adobe Flash Player 10.0 allows local users to cause a denial of
service (memory consumption and system crash).

Technical information:
1) Log data, item 0
Address = 6B427D3A
Message = Break on guarded memory page set by application while
writing to [07ED0000] - Shift+Run/Step to pass exception to the
program

2) CPU Disasm
Address Hex dump Command Comments
6B427D3A 881E MOV BYTE PTR DS:[ESI],BL

3) CPU

EAX 06F4B000
ECX 0243CC14
EDX 07ED0000
EBX 00000010
ESP 0243C9EC
EBP 00000003
ESI 07ED0000
EDI 0243CC14
EIP 6B427D3A Flash10e_ocx.6B427D3A

C 0 ES 0023 32bit 0(FFFFFFFF)
P 0 CS 001B 32bit 0(FFFFFFFF)
A 0 SS 0023 32bit 0(FFFFFFFF)
Z 0 DS 0023 32bit 0(FFFFFFFF)
S 0 FS 003B 32bit 7FFD9000(FFF)
T 0 GS 0000 NULL
D 0
O 0 LastErr 00000000 ERROR_SUCCESS
EFL 00250202 (NO,NB,NE,A,NS,PO,GE,G)
...

The rest is omitted.
For more information see Proof of Concept screen shot.

Proof of Concept code:
http://www.kil13r.info/data/aaa.zip

Proof of Concept screen shot:
http://www.kil13r.info/sa/aaa/ollydbg.jpg

Proof of Concept video:
http://www.youtube.com/watch?v=Z_YT_m7aBWk
Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    0 Files
  • 9
    Sep 9th
    0 Files
  • 10
    Sep 10th
    0 Files
  • 11
    Sep 11th
    0 Files
  • 12
    Sep 12th
    0 Files
  • 13
    Sep 13th
    0 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    0 Files
  • 17
    Sep 17th
    0 Files
  • 18
    Sep 18th
    0 Files
  • 19
    Sep 19th
    0 Files
  • 20
    Sep 20th
    0 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close