CVE-2005-2628: Medium severity Macromedia Flash Player vulnerability
Published Nov 5, 2005
·Updated
Macromedia Flash 6 and 7 (Flash.ocx) allows remote attackers to execute arbitrary code via a SWF file with a modified frame type identifier that is used as an out-of-bounds array index to a function pointer.
Affected Software
8 affected components
Macromedia Flash Player=6.0.79.0
Macromedia Flash Player=7.0_r19
Macromedia Flash Player=6.0.65.0
Macromedia Flash Player=6.0.29.0
Macromedia Flash Player=6.0
Macromedia Flash Player=6.0.47.0
Macromedia Flash Player=6.0.40.0
Macromedia Flash Player=7.0.19.0
Remediation
Patch Available
Event History
Nov 5, 2005
CVE Published
11:02 AM
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2628?
CVE-2005-2628 is considered critical due to the potential for remote code execution.
2
How do I fix CVE-2005-2628?
To mitigate CVE-2005-2628, upgrade to a patched version of Macromedia Flash Player that addresses this vulnerability.
3
What versions are affected by CVE-2005-2628?
CVE-2005-2628 affects Macromedia Flash Player versions 6.0.x and 7.0.x.
4
What are the symptoms of an exploit for CVE-2005-2628?
Exploitation of CVE-2005-2628 may result in arbitrary code execution on affected systems.
5
Who is vulnerable to CVE-2005-2628?
Users of Macromedia Flash Player versions 6 and 7, particularly those who open malicious SWF files, are vulnerable to CVE-2005-2628.