Severity:
High
Vendor:
Macromedia
Systems Affected:
Macromedia Flash 6 (on all Windows platforms)
Macromedia Flash 7 (on all Windows platforms)
Overview:
eEye Digital Security has discovered a vulnerability in Macromedia Flash
Player versions 6 and 7 that will allow an attacker to run arbitrary
code in the context of the logged in user. An array boundary condition
may be violated by a malicious SWF file in order to redirect execution
into attacker-supplied data.
Vendor Status:
Macromedia has addressed this issue in the following security bulletin;
http://www.macromedia.com/devnet/sec...mpsb05-07.html