PT-2017-18327 · Swftools · Swftools
Publicado
2017-07-05
·
Atualizado
2017-07-13
·
CVE-2017-8420
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
SWFTools version 2013-04-09-1007
Description
The issue arises from the mishandling of a malformed TTF file by the font2swf component, leading to a potential Denial of Service (DoS) due to an Access Violation. This can be triggered when
font2swf processes a specially crafted TTF file, causing the program to crash.Recommendations
For SWFTools version 2013-04-09-1007, consider avoiding the use of malformed TTF files with the
font2swf component until a fix is available. As a temporary workaround, restrict the input to font2swf to prevent the processing of potentially malicious TTF files.Exploit
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Swftools