>> Adobe Flash Media Server Remote Command Execution Vulnerabilities
Title : Adobe Flash Media Server Remote Command Execution Vulnerabilities VUPEN ID : VUPEN/ADV-2008-0538 CVE ID : CVE-2007-6148 - CVE-2007-6149 - CVE-2007-6431
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-02-13
Technical Description
Multiple vulnerabilities have been identified in Adobe Flash Media Server, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system.
The first issue is caused by integer overflow errors in the Edge server component when parsing malformed RTMP (Real Time Message Protocol) messages sent to port 1935/TCP or 19350/TCP, which could be exploited by remote attackers to crash an affected server or execute arbitrary code with SYSTEM privileges.
The second vulnerability is caused by a memory corruption error in the Edge server component when parsing certain sequence of requests sent to port 1935/TCP or 19350/TCP, which could be exploited by remote attackers to crash an affected server or execute arbitrary code with SYSTEM privileges.