PT-2017-18327 · Swftools · Swftools

Published

2017-07-05

·

Updated

2017-07-13

·

CVE-2017-8420

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions SWFTools version 2013-04-09-1007
Description The issue arises from the mishandling of a malformed TTF file by the font2swf component, leading to a potential Denial of Service (DoS) due to an Access Violation. This can be triggered when font2swf processes a specially crafted TTF file, causing the program to crash.
Recommendations For SWFTools version 2013-04-09-1007, consider avoiding the use of malformed TTF files with the font2swf component until a fix is available. As a temporary workaround, restrict the input to font2swf to prevent the processing of potentially malicious TTF files.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-8420

Affected Products

Swftools