Adobe Flash - H264 Parsing Out-of-Bounds Read
Author: Google Security Research
type: dos
platform: multiple
port:
date_added: 2016-02-17
date_updated: 2016-02-19
verified: 1
codes:
tags:
aliases:
screenshot_url:
application_url:
Source: https://code.google.com/p/google-security-research/issues/detail?id=632
There is an out-of-bounds read in H264 parsing, a fuzzed file is attached. To load, load LoadMP4.swf with the URL parameter file=compute_poc.flv from a remote server.
Proof of Concept:
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/39464.zip