>> Adobe Macromedia Flash Player Code Execution and Denial of Service Vulnerabilities
Title : Adobe Macromedia Flash Player Code Execution and Denial of Service Vulnerabilities VUPEN ID : VUPEN/ADV-2006-2702 CVE ID : CVE-2006-3587 - CVE-2006-3588
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-07-07
Technical Description
Multiple vulnerabilities have been identified in Adobe Macromedia Flash Player, which could be exploited by attackers to take complete control of an affected system or cause a denial of service.
The first vulnerability is due to improper memory access errors when processing malformed SWF files, which could be exploited by attackers to execute arbitrary commands by tricking a user into visiting a malicious web page.
The second issue is due to an unspecified error when handling malformed SWF files, which could be exploited by malicious web sites to crash a web browser linked against a vulnerable player.