CVE-2009-3799
Adobe Flash Player ActionScript Exception Handler Integer Overflow Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Integer overflow in the Verifier::parseExceptionHandlers function in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allows remote attackers to execute arbitrary code via an SWF file with a large exception_count value that triggers memory corruption, related to "generation of ActionScript exception handlers."
Desbordamiento de entero en la funcion Verifier::parseExceptionHandlers en Adobe Flash Player anteriores a v10.0.42.34 y Adobe AIR anteriores a v1.5.3 permite a atacantes remotos ejecutar código arbitrario a través de un fichero SWF con un valor de "exception_count" que inicia una corrupción de la memoria, relacionado con la "generación de administradores de excepciones de ActionScript".
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Adobe Flash Player. User interaction is required to exploit this vulnerability in that the target must visit a malicious web page or open a malicious SWF file.
The specific flaw exists in the generation of ActionScript exception handlers. In Verifier::parseExceptionHandlers(), a large value for exception_count will result in an integer overflow condition leading to a memory corruption which can be leveraged to execute arbitrary code under the context of the currently logged in user.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-10-26 CVE Reserved
- 2009-12-09 CVE Published
- 2024-08-07 CVE Updated
- 2024-08-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-189: Numeric Errors
CAPEC
References (25)
URL | Tag | Source |
---|---|---|
http://osvdb.org/60889 | Vdb Entry | |
http://secunia.com/advisories/37902 | Third Party Advisory | |
http://secunia.com/advisories/38241 | Third Party Advisory | |
http://support.apple.com/kb/HT4004 | X_refsource_confirm | |
http://www.securityfocus.com/archive/1/508334/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/37199 | Vdb Entry | |
http://www.us-cert.gov/cas/techalerts/TA09-343A.html | Third Party Advisory | |
http://www.vupen.com/english/advisories/2010/0173 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/54635 | Vdb Entry | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16315 | Signature | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7191 | Signature | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8208 | Signature |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://securitytracker.com/id?1023306 | 2018-10-30 | |
http://securitytracker.com/id?1023307 | 2018-10-30 | |
http://www.adobe.com/support/security/bulletins/apsb09-19.html | 2018-10-30 | |
http://www.redhat.com/support/errata/RHSA-2009-1657.html | 2018-10-30 | |
http://www.redhat.com/support/errata/RHSA-2009-1658.html | 2018-10-30 | |
http://www.vupen.com/english/advisories/2009/3456 | 2018-10-30 | |
http://zerodayinitiative.com/advisories/ZDI-09-093 | 2018-10-30 | |
https://bugzilla.redhat.com/show_bug.cgi?id=543857 | 2009-12-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Adobe Search vendor "Adobe" | Adobe Air Search vendor "Adobe" for product "Adobe Air" | <= 1.5.2 Search vendor "Adobe" for product "Adobe Air" and version " <= 1.5.2" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Adobe Air Search vendor "Adobe" for product "Adobe Air" | 1.0 Search vendor "Adobe" for product "Adobe Air" and version "1.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Adobe Air Search vendor "Adobe" for product "Adobe Air" | 1.0.1 Search vendor "Adobe" for product "Adobe Air" and version "1.0.1" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Adobe Air Search vendor "Adobe" for product "Adobe Air" | 1.1 Search vendor "Adobe" for product "Adobe Air" and version "1.1" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Adobe Air Search vendor "Adobe" for product "Adobe Air" | 1.5.1 Search vendor "Adobe" for product "Adobe Air" and version "1.5.1" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | <= 10.0.32.18 Search vendor "Adobe" for product "Flash Player" and version " <= 10.0.32.18" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 7.0 Search vendor "Adobe" for product "Flash Player" and version "7.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 7.0.1 Search vendor "Adobe" for product "Flash Player" and version "7.0.1" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 7.0.25 Search vendor "Adobe" for product "Flash Player" and version "7.0.25" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 7.0.63 Search vendor "Adobe" for product "Flash Player" and version "7.0.63" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 7.0.69.0 Search vendor "Adobe" for product "Flash Player" and version "7.0.69.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 7.0.70.0 Search vendor "Adobe" for product "Flash Player" and version "7.0.70.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 7.1 Search vendor "Adobe" for product "Flash Player" and version "7.1" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 7.1.1 Search vendor "Adobe" for product "Flash Player" and version "7.1.1" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 7.2 Search vendor "Adobe" for product "Flash Player" and version "7.2" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 8 Search vendor "Adobe" for product "Flash Player" and version "8" | pro |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 8 Search vendor "Adobe" for product "Flash Player" and version "8" | professional |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 8.0 Search vendor "Adobe" for product "Flash Player" and version "8.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 8.0 Search vendor "Adobe" for product "Flash Player" and version "8.0" | basic |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 8.0 Search vendor "Adobe" for product "Flash Player" and version "8.0" | pro |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 8.0.24.0 Search vendor "Adobe" for product "Flash Player" and version "8.0.24.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 8.0.34.0 Search vendor "Adobe" for product "Flash Player" and version "8.0.34.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 8.0.35.0 Search vendor "Adobe" for product "Flash Player" and version "8.0.35.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 8.0.39.0 Search vendor "Adobe" for product "Flash Player" and version "8.0.39.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 9.0 Search vendor "Adobe" for product "Flash Player" and version "9.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 9.0.16 Search vendor "Adobe" for product "Flash Player" and version "9.0.16" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 9.0.18d60 Search vendor "Adobe" for product "Flash Player" and version "9.0.18d60" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 9.0.20 Search vendor "Adobe" for product "Flash Player" and version "9.0.20" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 9.0.20.0 Search vendor "Adobe" for product "Flash Player" and version "9.0.20.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 9.0.28 Search vendor "Adobe" for product "Flash Player" and version "9.0.28" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 9.0.28.0 Search vendor "Adobe" for product "Flash Player" and version "9.0.28.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 9.0.31 Search vendor "Adobe" for product "Flash Player" and version "9.0.31" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 9.0.31.0 Search vendor "Adobe" for product "Flash Player" and version "9.0.31.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 9.0.45.0 Search vendor "Adobe" for product "Flash Player" and version "9.0.45.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 9.0.47.0 Search vendor "Adobe" for product "Flash Player" and version "9.0.47.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 9.0.112.0 Search vendor "Adobe" for product "Flash Player" and version "9.0.112.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 9.0.114.0 Search vendor "Adobe" for product "Flash Player" and version "9.0.114.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 9.0.115.0 Search vendor "Adobe" for product "Flash Player" and version "9.0.115.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 9.0.124.0 Search vendor "Adobe" for product "Flash Player" and version "9.0.124.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 9.0.155.0 Search vendor "Adobe" for product "Flash Player" and version "9.0.155.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 9.0.159.0 Search vendor "Adobe" for product "Flash Player" and version "9.0.159.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 9.125.0 Search vendor "Adobe" for product "Flash Player" and version "9.125.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 10.0.0.584 Search vendor "Adobe" for product "Flash Player" and version "10.0.0.584" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 10.0.12.10 Search vendor "Adobe" for product "Flash Player" and version "10.0.12.10" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 10.0.12.36 Search vendor "Adobe" for product "Flash Player" and version "10.0.12.36" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 10.0.22.87 Search vendor "Adobe" for product "Flash Player" and version "10.0.22.87" | - |
Affected
|