Flash Failing Checks On uint Capacity Field
Posted by deepcore on September 30, 2015 – 7:56 am
The latest version of the Vector.primitive length check in Flash 18,0,0,232 is not robust against memory corruptions such as heap overflows. While it is no longer possible to obviously bypass the length check there is still unguarded data in the object which could be corrupted to serve as a useful primitive.
Post a reply
You must be logged in to post a comment.