HTTP: Adobe Shockwave Player Lnam Chunk Processing Buffer Overflow

This signature detects attemps to exploit a code execution vulnerability in Adobe Shockwave Player. It is due to a stack buffer overflow when processing maliciously crafted DIR files containing Lnam Chunks. A remote attacker can exploit this by enticing a target user to visit a maliciously crafted Web site. A successful attack can result in execution of arbitrary code within the security context of the currently logged on user. An unsuccessful attempt can terminate the affected application abnormally.

Extended Description

Adobe Shockwave Player is prone to a stack-overflow vulnerability. Attackers can exploit this issue to execute arbitrary code in the context of the user running the affected application. Failed attacks may cause a denial-of-service condition. Adobe Shockwave Player versions prior to 11.5.9.615 are vulnerable.

Affected Products

Adobe shockwave_player

References

BugTraq: 44516

CVE: CVE-2010-3655

Short Name
HTTP:STC:ADOBE:XFIR-LNAM
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Adobe Buffer CVE-2010-3655 Chunk Lnam Overflow Player Processing Shockwave bid:44516
Release Date
12/10/2010
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Adobe

CVSS Score

9.3

Found a potential security threat?