HTTP: Adobe Flash Player JPEG Parsing Heap Overflow

This signature detects attempts to exploit a known vulnerability against Adobe Flash Player. A successful attack can lead to memory corruption and arbitrary code execution.

Extended Description

Heap-based buffer overflow in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allows remote attackers to execute arbitrary code via crafted dimensions of JPEG data in an SWF file.

Affected Products

Adobe flash_player

References

BugTraq: 37199

CVE: CVE-2009-3794

Short Name
HTTP:STC:ADOBE:FLASH-PL-JPEG-OF
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
Adobe CVE-2009-3794 Flash Heap JPEG Overflow Parsing Player bid:37199
Release Date
06/09/2015
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Adobe

CVSS Score

9.3

Found a potential security threat?