Adobe Flash TextField.maxChars Use-After-Free
Posted by deepcore on April 1, 2016 – 8:53 am
There is a use-after-free in the TextField.maxChars setter in Adobe Flash. If the maxChars the field is set to is an object with valueOf defined, the valueOf function can free the field’s parent object, which is then used.
Post a reply
You must be logged in to post a comment.