CVE-2007-3456
Publication date 11 July 2007
Last updated 17 July 2025
Ubuntu priority
Description
Integer overflow in Adobe Flash Player 9.0.45.0 and earlier might allow remote attackers to execute arbitrary code via a large length value for a (1) Long string or (2) XML variable type in a crafted (a) FLV or (b) SWF file, related to an "input validation error," including a signed comparison of values that are assumed to be non-negative.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| flashplugin-nonfree | ||