CVE-2007-3456: Input Validation
Integer overflow in Adobe Flash Player 9.0.45.0 and earlier might allow remote attackers to execute arbitrary code via a large length value for a (1) Long string or (2) XML variable type in a crafted (a) FLV or (b) SWF file, related to an "input validation error," including a signed comparison of values that are assumed to be non-negative.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-3456?
CVE-2007-3456 is considered a critical vulnerability due to the potential for remote code execution.
How do I fix CVE-2007-3456?
To fix CVE-2007-3456, you should update your Adobe Flash Player to version 9.0.46.0 or later.
Who is affected by CVE-2007-3456?
CVE-2007-3456 affects users of Adobe Flash Player version 9.0.45.0 and earlier.
What type of attack is associated with CVE-2007-3456?
CVE-2007-3456 is associated with remote code execution attacks through crafted FLV or SWF files.
How does CVE-2007-3456 exploit vulnerabilities?
CVE-2007-3456 exploits vulnerabilities through integer overflow caused by improper handling of large length values in Flash files.