PT-2008-1539 · Adobe · Flash Media Server+1
Published
2008-02-13
·
Updated
2017-07-29
·
CVE-2007-6149
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Adobe Flash Media Server versions prior to 2.0.5
Adobe Connect Enterprise Server versions prior to 6 SP3
Description
The issue is related to multiple integer overflows in the Edge server of Adobe Flash Media Server and Adobe Connect Enterprise Server. This allows remote attackers to execute arbitrary code via a Real Time Message Protocol (RTMP) message with a crafted integer field that is used for allocation.
Recommendations
For Adobe Flash Media Server versions prior to 2.0.5, update to version 2.0.5 or later.
For Adobe Connect Enterprise Server versions prior to 6 SP3, update to version 6 SP3 or later.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Connect Enterprise Server
Flash Media Server