PT-2017-18322 · Swftools · Swftools

Chunibalon

·

Published

2017-05-01

·

Updated

2017-05-12

·

CVE-2017-8401

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions SWFTools version 0.9.2
Description The issue is caused by an out-of-bounds read of heap data in the png load() function, which can be triggered by a malformed PNG file. This can lead to a denial of service (DoS) and can be exploited by attackers.
Recommendations For SWFTools version 0.9.2, consider avoiding the use of the png2swf tool with untrusted PNG files until a patch is available. As a temporary workaround, restrict the handling of PNG files to trusted sources to minimize the risk of exploitation.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-8401
DLA-995-1

Affected Products

Swftools