HTTP: TrafficIQ WMF Malformed Header

This signature detects a Windows Meta File (WMF) with invalid options in its header generated by TrafficIQ, a traffic generator. The WMF generated by TrafficIQ is not malicious and does not crash Internet Explorer.

Extended Description

Microsoft Internet Explorer is affected by an WMF image-parsing memory-corruption vulnerability. This issue is allegedly due to an integer-overflow flaw that leads to corrupted heap memory. This problem presents itself when a user views a malicious WMF-formatted file containing specially crafted data. This issue allows remote attackers to execute arbitrary machine code in the context of the affected application. Failed exploitation attempts likely result in crashing the application.

Affected Products

Nortel_networks self-service_media_processing_server,Nortel_networks optivity_telephony_manager_tm-cs1000

Short Name
SCAN:II:TIQ-WMF-MAL-HEADER
Severity
Warning
Recommended
False
Recommended Action
Drop
Category
SCAN
Keywords
CVE-2006-0020 Header Malformed TrafficIQ WMF bid:16516
Release Date
10/18/2006
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Nortel_networks

Avaya

CVSS Score

9.3

Found a potential security threat?