HTTP: Adobe Flash Player Race Condition Between Text Drawing And NetConnection Object

This signature detects attempts to exploit a known vulnerability in the Adobe Acrobat Reader. A successful attack can lead to a user after free condition and arbitrary remote code execution within the context of the user.

Extended Description

Adobe Flash Player before 11.7.700.242 and 11.8.x before 11.8.800.168 on Windows and Mac OS X, before 11.2.202.310 on Linux, before 11.1.111.73 on Android 2.x and 3.x, and before 11.1.115.81 on Android 4.x; Adobe AIR before 3.8.0.1430; and Adobe AIR SDK & Compiler before 3.8.0.1430 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-3362, CVE-2013-3363, and CVE-2013-5324.

Affected Products

Adobe air_sdk

References

CVE: CVE-2013-3361

Short Name
HTTP:STC:ADOBE:TEXT-NETCONNECT
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Adobe And Between CVE-2013-3361 Condition Drawing Flash NetConnection Object Player Race Text
Release Date
11/25/2013
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3761
False Positive
Unknown
Vendors

Adobe

CVSS Score

10.0

Found a potential security threat?