PT-2017-11742 · Swftools · Swftools
Published
2017-07-07
·
Updated
2017-07-13
·
CVE-2017-11101
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SWFTools version 0.9.2
Description
The issue arises when SWFTools processes a crafted file using swfcombine, resulting in a NULL Pointer Dereference in the
swf Relocate() function located in lib/modules/swftools.c.Recommendations
For SWFTools version 0.9.2, consider avoiding the use of swfcombine with untrusted files until a patch is available. As a temporary workaround, restrict access to the
swf Relocate() function to minimize the risk of exploitation.Exploit
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Swftools