CVE-2007-6149

Severity CVSS v4.0:
Pending analysis
Type:
CWE-189 Numeric Errors
Publication date:
13/02/2008
Last modified:
09/04/2025

Description

Multiple integer overflows in the Edge server in Adobe Flash Media Server 2 before 2.0.5, and Connect Enterprise Server 6 before SP3, allow remote attackers to execute arbitrary code via a Real Time Message Protocol (RTMP) message with a crafted integer field that is used for allocation.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:adobe:connect_enterprise_server:*:sp2:*:*:*:*:*:* 6 (including)
cpe:2.3:a:adobe:flash_media_server_2:*:*:*:*:*:*:*:* 2.0.4 (including)