CVE-2007-2500
Publication date 4 May 2007
Last updated 17 July 2025
Ubuntu priority
server/parser/sprite_definition.cpp in GNU Gnash (aka GNU Flash Player) 0.7.2 allows remote attackers to execute arbitrary code via a large number of SHOWFRAME elements within a DEFINESPRITE element, which triggers memory corruption and enables the attacker to call free with an arbitrary address, probably resultant from a buffer overflow.
Status
Package | Ubuntu Release | Status |
---|---|---|
gnash | 7.10 gutsy |
Fixed 0.7.2+cvs20070518.1557-1
|
7.04 feisty |
Fixed 0.7.2-1ubuntu0.1
|
|
6.10 edgy | Not in release | |
6.06 LTS dapper | Not in release |