This vulnerability is an instance of a memory corruption vulnerability when parsing shape outline. Specifically, the vulnerability is caused by a crafted SWF file with an invalid DefineFont3 tag definition of number of symbol shapes. It causes an out of bounds memory access, which sometimes triggers access violation exception. |