Adobe Flash - Info Leak in Image Inflation



EKU-ID: 48470 CVE: CVE-2018-4934 OSVDB-ID:
Author: Google Security Research Published: 2018-04-24 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


The attached image causes an info leak in image inflation. It occasionally crashes when rendered, otherwise it displays uninitialized memory as pixels.

To reproduce, put the attached images on a webserver and vist: http://127.0.0.1?img=inflate.png.


Proof of Concept:
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/44528.zip