HTTP: TrafficIQ WMF Malformed Header
This signature detects a Windows Meta File (WMF) with invalid options in its header generated by TrafficIQ, a traffic generator. The WMF generated by TrafficIQ is not malicious and does not crash Internet Explorer.
Extended Description
Microsoft Internet Explorer is affected by an WMF image-parsing memory-corruption vulnerability. This issue is allegedly due to an integer-overflow flaw that leads to corrupted heap memory. This problem presents itself when a user views a malicious WMF-formatted file containing specially crafted data. This issue allows remote attackers to execute arbitrary machine code in the context of the affected application. Failed exploitation attempts likely result in crashing the application.
Affected Products
Nortel_networks self-service_media_processing_server,Nortel_networks optivity_telephony_manager_tm-cs1000
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Nortel_networks
Avaya
9.3