
As we discusses in our previous blog on recent Adobe 0-day(CVE-2015-5119), there are two more vulnerabilities that surfaced from the same HackingTeam data leak:
All three vulnerabilities are use-after-free vulnerabilities; although they occur in different classes. These vulnerabilities trigger the bug by overriding the 'valueOf()' function of these classes. During the override, the associated object is either freed or relocated. This makes the associated address invalid which inadvertantly triggers the vulnerability.
Here's an example of CVE-2015-5123 where a 'BitmapData' object is created and disposed by overriding 'valueOf()' function:

Sonicwall team has written following signature that protect our customers from these exploits:
Share This Article

An Article By
An Article By
Security News
Security News