InformationWeek reports that Security Advisory 2010-48, which was issued to fix a plugin parameter array crash, actually caused a crash that showed indications of memory corruption. The security update states:
In certain circumstances, properties in the plugin instance's parameter array could be freed prematurely leaving a dangling pointer that the plugin could execute, potentially calling into attacker-controlled memory.
Comments
Post new comment