[] NeoSense

Adobe Flash - AVC Processing Out-of-Bounds Read

Author: Google Security Research
type: dos
platform: linux
port: 
date_added: 2018-08-27 
date_updated: 2018-08-27 
verified: 1 
codes: CVE-2018-12827 
tags: Out Of Bounds
aliases:  
screenshot_url:  
application_url: 

The attached fuzz file causes an out-of-bounds read in AVC processing. To reproduce the issue, put both attached files on a server, and vist:

http://127.0.0.1/LoadMP4.swf?file=transpose.mp4

This issue reproduces on Chrome and Firefox for Linux.


Proof of Concept:
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/45268.zip