Short Name |
HTTP:STC:SWF:MAL-SWF-OF |
---|---|
Severity |
Low |
Recommended |
No |
Category |
HTTP |
Keywords |
Macromedia Flash ActiveX Buffer Overflow |
Release Date |
2003/04/22 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to download a malicious Macromedia Flash document. Attackers can send a maliciously crafted Flash document and manipulate an ActiveX control to execute arbitrary shellcode on the host.
Macromedia produces an ActiveX plugin version of the Flash Player, designed to work with Microsoft Internet Explorer. A vulnerability has been reported in some versions of this component. A buffer overflow exists in the parameter handling of this component. If an oversized parameter is including in the URI passed to the ActiveX component, process memory is corrupted. Exploitation of this vulnerability may result in arbitrary code execution when a malicious web page is viewed. It may be possible to exploit this vulnerability through HTML formatted email, this has not however been confirmed.