PT-2017-18327 · Swftools · Swftools
Published
2017-07-05
·
Updated
2017-07-13
·
CVE-2017-8420
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
SWFTools version 2013-04-09-1007
Description
The issue arises from the mishandling of a malformed TTF file by the font2swf component, leading to a potential Denial of Service (DoS) due to an Access Violation. This can be triggered when
font2swf processes a specially crafted TTF file, causing the program to crash.Recommendations
For SWFTools version 2013-04-09-1007, consider avoiding the use of malformed TTF files with the
font2swf component until a fix is available. As a temporary workaround, restrict the input to font2swf to prevent the processing of potentially malicious TTF files.Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Swftools