CVE-2007-2500

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/05/2007
Last modified:
09/04/2025

Description

server/parser/sprite_definition.cpp in GNU Gnash (aka GNU Flash Player) 0.7.2 allows remote attackers to execute arbitrary code via a large number of SHOWFRAME elements within a DEFINESPRITE element, which triggers memory corruption and enables the attacker to call free with an arbitrary address, probably resultant from a buffer overflow.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gnu:flash_player:*:*:*:*:*:*:*:* 0.7.2 (including)