PT-2024-21356 · Swftools · Swftools
Guangbuming
·
Published
2024-03-05
·
Updated
2025-04-01
·
CVE-2024-26333
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
swftools version 0.9.2
Description
The issue is related to a segmentation violation in the function
free lines at swftools/lib/modules/swfshape.c. This indicates a potential memory access error that could lead to unexpected program behavior or crashes.Recommendations
For swftools version 0.9.2, as a temporary workaround, consider disabling the
free lines function until a patch is available. However, since this is a core functionality issue, the best course of action would be to wait for an official update or patch from the developers that addresses the segmentation violation. At the moment, there is no information about a newer version that contains a fix for this issue.Exploit
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Swftools