CVE-2009-3794: Integer Overflow
Heap-based buffer overflow in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allows remote attackers to execute arbitrary code via crafted dimensions of JPEG data in an SWF file.
Other sources
On next Tuesday, 2009-12-08, Adobe is planning to release an update for Adobe Flash Player 10.0.32.18 and earlier versions, to address multiple security issues allowing code execution, whose description is detailed in the Adobe Security Bulletin APSB09-19:
http://www.adobe.com/support/security/bulletins/apsb09-19.html
Quoting Adobe Security Bulletin: -------------------------------- This update resolves a vulnerability in the parsing of JPEG data that could potentially lead to code execution (CVE-2009-3794).
This update resolves a data injection vulnerability that could potentially lead to code execution (CVE-2009-3796).
This update resolves a memory corruption vulnerability that could potentially lead to code execution (CVE-2009-3797).
This update resolves a memory corruption vulnerability that could potentially lead to code execution (CVE-2009-3798).
This update resolves an integer overflow vulnerability that could potentially lead to code execution (CVE-2009-3799).
This update resolves multiple crash vulnerabilities that could potentially lead to code execution (CVE-2009-3800).
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2009-3794?
CVE-2009-3794 has a high severity rating due to its potential for remote code execution.
How do I fix CVE-2009-3794?
To fix CVE-2009-3794, update Adobe Flash Player to version 10.0.42.34 or later, or Adobe AIR to version 1.5.3 or later.
What systems are affected by CVE-2009-3794?
CVE-2009-3794 affects Adobe Flash Player versions before 10.0.42.34 and Adobe AIR versions prior to 1.5.3.
Can CVE-2009-3794 be exploited remotely?
Yes, CVE-2009-3794 can be exploited remotely through crafted SWF files.
What type of vulnerability is CVE-2009-3794 classified as?
CVE-2009-3794 is classified as a heap-based buffer overflow vulnerability.