PT-2022-11566 · Swftools · Swftools

Cxlzffo

·

Published

2022-05-31

·

Updated

2022-06-08

·

CVE-2021-42203

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions swftools versions through 20201222
Description An issue exists in the function swf FontExtract DefineTextCallback() located in swftext.c, allowing an attacker to cause code execution due to a heap-use-after-free.
Recommendations For versions through 20201222, consider disabling the swf FontExtract DefineTextCallback() function as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-42203

Affected Products

Swftools