CVE-2005-3591: Input Validation
Macromedia Flash plugin (1) Flash.ocx 7.0.19.0 (Windows) and earlier and (2) libflashplayer.so before 7.0.25.0 (Unix) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via parameters to the ActionDefineFunction ActionScript call in a SWF file, which causes an improper memory access condition, a different vulnerability than CVE-2005-2628.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-3591?
CVE-2005-3591 is considered to have a high severity due to its potential to allow remote attackers to cause a denial of service and execute arbitrary code.
How do I fix CVE-2005-3591?
To fix CVE-2005-3591, users should upgrade to the latest version of Macromedia Flash Player that patches the vulnerability.
What versions are affected by CVE-2005-3591?
CVE-2005-3591 affects Flash Player versions 6.0.29.0 to 7.0.19.0 on Windows and earlier versions of libflashplayer.so on Unix.
What are the potential impacts of CVE-2005-3591?
The potential impacts of CVE-2005-3591 include crashing the Flash Player and possible execution of arbitrary code by an attacker.
Are there any workarounds for CVE-2005-3591?
A potential workaround for CVE-2005-3591 is to disable or uninstall the Flash Player until an upgrade can be performed.