Integer overflow in the GnashImage::size method in libbase/GnashImage.h in GNU Gnash 0.8.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SWF file, which triggers a heap-based buffer overflow.
It was reported [1] that an integer overflow in GNU Gnash's GnashImage::size() method could be exploited to cause a heap-based buffer overflow when opening certain specially-crafted SWF files. If a user were tricked into opening a malicious SWF file it cause cause Gnash to crash or, possibly, execute arbitrary code with the permissions of the user running Gnash.
The flaw was reported in 0.8.10 and is fixed in git [2].
[1] http://secunia.com/advisories/47183 [2] http://git.savannah.gnu.org/cgit/gnash.git/commit/?id=bb4dc77eecb6ed1b967e3ecbce3dac6c5e6f1527
A security flaw was found in the way Shockwave Flash plug-in of the gnash, a GNU flash movie player, performed management of HTTP cookies (they were stored under /tmp directory with world-readable permissions). A local attacker could use this flaw to obtain sensitive information.
References: [1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=649384
A security flaw was found in the way Shockwave Flash plug-in of the gnash, a GNU flash movie player, performed management of HTTP cookies (they were stored under /tmp directory with world-readable permissions). A local attacker could use this flaw to obtain sensitive information.
References: [1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=649384
The configure script in gnash 0.8.8 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/gnash-configure-errors.$$, (2) /tmp/gnash-configure-warnings.$$, or (3) /tmp/gnash-configure-recommended.$$ files.