> allocated from the program stack. The uninitialized data you see in a 
> handshake packet is return addresses, function parameters and local variable
> allocations previously used in other parts of the program!

Bad bad bad.

That's a potential security hole, since the player is sending
unitialized memory, it might contains anything - including part of your
passwords and SSH keys. Can we get Adobe to fix that thing ??

Nicolas

_______________________________________________
osflash mailing list
[email protected]
http://osflash.org/mailman/listinfo/osflash_osflash.org

Reply via email to