Macromedia produces an ActiveX plugin version of the Flash Player, designed to work with Microsoft Internet Explorer. A vulnerability has been reported in some versions of this component. A buffer overflow exists in the parameter handling of this component. If an oversized parameter is including in the URI passed to the ActiveX component, process memory is corrupted. Exploitation of this vulnerability may result in arbitrary code execution when a malicious web page is viewed. It may be possible to exploit this vulnerability through HTML formatted email, this has not however been confirmed.
Macromedia produces an ActiveX plugin version of the Flash Player, designed to work with Microsoft Internet Explorer. A vulnerability has been reported in some versions of this component. A buffer overflow exists in the parameter handling of this component. If an oversized parameter is including in the URI passed to the ActiveX component, process memory is corrupted. Exploitation of this vulnerability may result in arbitrary code execution when a malicious web page is viewed. It may be possible to exploit this vulnerability through HTML formatted email, this has not however been confirmed.