CVE-2009-3799: Integer Overflow
Integer overflow in the Verifier::parseExceptionHandlers function in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allows remote attackers to execute arbitrary code via an SWF file with a large exceptioncount value that triggers memory corruption, related to "generation of ActionScript exception handlers."
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2009-3799?
CVE-2009-3799 is considered critical due to its potential for arbitrary code execution.
How do I fix CVE-2009-3799?
To fix CVE-2009-3799, upgrade Adobe Flash Player to version 10.0.42.34 or later and Adobe AIR to version 1.5.3 or later.
What platforms are affected by CVE-2009-3799?
CVE-2009-3799 affects various versions of Adobe Flash Player and Adobe AIR across multiple operating systems.
Can CVE-2009-3799 be exploited remotely?
Yes, CVE-2009-3799 can be exploited remotely through specially crafted SWF files.
What is the nature of the vulnerability in CVE-2009-3799?
CVE-2009-3799 involves an integer overflow in the Verifier::parseExceptionHandlers function leading to memory corruption.