Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-62217
HistoryJun 10, 2022 - 12:00 a.m.

Swftools post-release use vulnerability

2022-06-1000:00:00
China National Vulnerability Database
www.cnvd.org.cn
11
swftools
post-release
usage vulnerability
swftext.c
code execution
heap-based
cnvd

EPSS

0.001

Percentile

36.3%

Swftools is a set of utilities for working with Adobe Flash files (SWF files). swftools 2020-12-22 and earlier versions contain a post-release usage vulnerability that stems from the function swf_FontExtract_DefineTextCallback() located in swftext.c in swftext.c has a heap-based post-release reuse issue. An attacker could exploit this vulnerability to enable code execution.

EPSS

0.001

Percentile

36.3%