Rule Category

FILE-FLASH -- Snort has detected suspicious traffic via the Adobe Flash Player. Flash is a common target of code execution, overflow, DoS, and memory corruption attacks in particular, via swifs, action scripts, etc. Many networks block Flash altogether; the application will be deprecated in 2020.

Alert Message

FILE-FLASH Adobe Flash Player FLV Nellymoser audio codec stack overflow attempt

Rule Explanation

This event is generated when an attacker attempts to exploit a stack overflow vulnerability in Adobe Flash Player. Impact: Attempted User Privilege Gain Details: This rule checks for attempts to exploit a stack overflow vulnerability in Adobe Flash Player's parsing of FLV files with Nellymoser audio codecs. Ease of Attack:

What To Look For

No information provided

Known Usage

No public information

False Positives

No known false positives

Contributors

Cisco Talos Intelligence Group

Rule Groups

No rule groups

CVE

Additional Links

Rule Vulnerability

CVE Additional Information

This product uses data from the NVD API but is not endorsed or certified by the NVD.
CVE-2015-4432
Loading description