HTTP: VML Recolorinfo Heap Overflow

This signature detects attempts to exploit a known vulnerability against the Vector Markup Language (VML) implementation in various browsers. An attacker could attempt to trick a user to view a hostile Web page or view a file containing vulnerable code, causing a heap overflow and ultimately taking over the remote computer.

Extended Description

Microsoft Windows is prone to a buffer-overrun vulnerability that arises because of an error in the processing of Vector Markup Language documents. An attacker can exploit this issue to execute arbitrary code within the context of the affected application.

Affected Products

Avaya s8100_media_servers,Microsoft windows_2000_server

Short Name
HTTP:STC:VML-NUM-BOF
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2007-0024 CVE-2010-1179 Heap Overflow Recolorinfo VML bid:21930
Release Date
01/09/2007
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3728
False Positive
Unknown
Vendors

Nortel_networks

Microsoft

Avaya

CVSS Score

9.3

Found a potential security threat?