PT-2022-11561 · Swftools · Swftools

Cxlzf

·

Published

2022-05-31

·

Updated

2022-06-08

·

CVE-2021-42199

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions swftools versions through 20201222
Description An issue exists in the function swf FontExtract DefineTextCallback() located in swftext.c, allowing an attacker to cause code execution due to a heap buffer overflow.
Recommendations For versions through 20201222, consider disabling the swf FontExtract DefineTextCallback() function as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-42199

Affected Products

Swftools