First published: Tue Dec 08 2009(Updated: )
Integer overflow in the Verifier::parseExceptionHandlers function in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allows remote attackers to execute arbitrary code via an SWF file with a large exception_count value that triggers memory corruption, related to "generation of ActionScript exception handlers."
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/flash-plugin | <0:9.0.260.0-1.el3 | 0:9.0.260.0-1.el3 |
redhat/flash-plugin | <0:9.0.260.0-1.el4 | 0:9.0.260.0-1.el4 |
redhat/flash-plugin | <0:10.0.42.34-1.el5 | 0:10.0.42.34-1.el5 |
Adobe AIR SDK | =1.0 | |
Adobe Acrobat Reader | =9.125.0 | |
Adobe AIR SDK | =1.5.1 | |
Adobe Acrobat Reader | =8.0.24.0 | |
Adobe Acrobat Reader | =9.0.18d60 | |
Adobe Acrobat Reader | =7.1.1 | |
Adobe Acrobat Reader | =9.0.124.0 | |
Adobe Acrobat Reader | =9.0.47.0 | |
Adobe Acrobat Reader | =7.0.63 | |
Adobe Acrobat Reader | =7.0.70.0 | |
Adobe Acrobat Reader | =10.0.12.36 | |
Adobe Acrobat Reader | =8.0.35.0 | |
Adobe Acrobat Reader | =9.0.114.0 | |
Adobe Acrobat Reader | =8.0 | |
Adobe Acrobat Reader | =9.0.20.0 | |
Adobe Acrobat Reader | =9.0.31.0 | |
Adobe Acrobat Reader | =9.0.159.0 | |
Adobe Acrobat Reader | =9.0.112.0 | |
Adobe Acrobat Reader | =9.0.16 | |
Adobe Acrobat Reader | =8 | |
Adobe Acrobat Reader | =10.0.0.584 | |
Adobe Acrobat Reader | =9.0.28.0 | |
Adobe Acrobat Reader | =7.0.69.0 | |
Adobe Acrobat Reader | =9.0.155.0 | |
Adobe Acrobat Reader | =10.0.22.87 | |
Adobe Acrobat Reader | =9.0.28 | |
Adobe Acrobat Reader | =9.0.45.0 | |
Adobe Acrobat Reader | =7.0 | |
Adobe Acrobat Reader | =9.0.31 | |
Adobe Acrobat Reader | =7.2 | |
Adobe AIR SDK | <=1.5.2 | |
Adobe Acrobat Reader | =9.0.115.0 | |
Adobe Acrobat Reader | =7.0.25 | |
Adobe Acrobat Reader | =8.0 | |
Adobe Acrobat Reader | =8.0.39.0 | |
Adobe AIR SDK | =1.0.1 | |
Adobe Acrobat Reader | =8.0.34.0 | |
Adobe Acrobat Reader | =8 | |
Adobe AIR SDK | =1.1 | |
Adobe Acrobat Reader | =7.1 | |
Adobe Acrobat Reader | =10.0.12.10 | |
Adobe Acrobat Reader | <=10.0.32.18 | |
Adobe Acrobat Reader | =9.0.20 | |
Adobe Acrobat Reader | =7.0.1 | |
Adobe Acrobat Reader | =8.0 | |
Adobe Acrobat Reader | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-3799 is considered critical due to its potential for arbitrary code execution.
To fix CVE-2009-3799, upgrade Adobe Flash Player to version 10.0.42.34 or later and Adobe AIR to version 1.5.3 or later.
CVE-2009-3799 affects various versions of Adobe Flash Player and Adobe AIR across multiple operating systems.
Yes, CVE-2009-3799 can be exploited remotely through specially crafted SWF files.
CVE-2009-3799 involves an integer overflow in the Verifier::parseExceptionHandlers function leading to memory corruption.