|
HTML_IE_ActiveX_Loader_Heap_Corruption*
This signature requires a manual PAM tunable in order to detect and therefore block the ClassID associated with RealPlayer. Please be warned that this will also block any legitimate usage of the ActiveX control just as setting the kill bit would, as mentioned in the workaround information below.
*pam.content.clsid.activexloaderbo.blacklist
This tuning parameter adds a user defined CLSID to a blacklist for the HTML_IE_ActiveX_Loader_Heap_Corruption signature. The specified CLSID will be regarded as a security threat whenever it is detected. An example of proper usage is pam.content.clsid.activexloaderbo.blacklist=FDC7A535-4070-4B92-A0EA-D9994BCC0DC5.
It is also quite possible, depending on the way an exploit is crafted, that one of the below signatures would trigger and block an attack leveraging this vulnerability.
JavaScript_Shellcode_Detected JavaScript_NOOP_Sled |