CVE-2012-1175: GNU Gnash

Medium severity, CVSS 6.8. EPSS: 4.3% chance of exploitation in the next 30 days.

Integer overflow in the GnashImage::size method in libbase/GnashImage.h in GNU Gnash 0.8.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SWF file, which triggers a heap-based buffer overflow.

Affected products

  • GNU Gnash: version 0.8.10 only

Published 2012-08-26. Last modified 2026-06-16.