Adobe Flash TextField.setFormat Use-After-Free

The TextField setFormat method contains a use-after-free. If an integer parameter has valueOf defined, or the object parameter overrides a constructor, this method can free the TextField parent, which is subsequently used.

Leave a Reply