HTTP: Microsoft Windows Graphics Rendering Engine WMF Parsing Buffer Overflow

This signature detects attempts to exploit a known vulnerability in the Graphics Rendering Engine (GRE) component of Microsoft Windows. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the user.

Extended Description

Microsoft GDI+ is prone to a buffer-overflow vulnerability because the vector graphics linked library improperly allocates memory when parsing WMF image files. Successfully exploiting this issue would allow an attacker to corrupt memory and execute arbitrary code in the context of the currently logged-in user.

Affected Products

Nortel_networks self-service_mps_1000,Research_in_motion blackberry_unite!

References

BugTraq: 31021

CVE: CVE-2008-3014

Short Name
HTTP:STC:DL:MS-WMF-PARSE
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Buffer CVE-2008-3014 Engine Graphics Microsoft Overflow Parsing Rendering WMF Windows bid:31021
Release Date
10/13/2010
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3339
False Positive
Unknown
Vendors

Research_in_motion

Symantec

Hp

Hitachi

Nortel_networks

Microsoft

CVSS Score

9.3

Found a potential security threat?