Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2024-02992
HistoryJan 16, 2024 - 12:00 a.m.

SWFTools Buffer Overflow Vulnerability

2024-01-1600:00:00
China National Vulnerability Database
www.cnvd.org.cn
14
swftools
buffer overflow
vulnerability
png_read_chunk
boundary error
memory allocation
attack

AI Score

7.2

Confidence

High

EPSS

0

Percentile

12.7%

SWFTools is a set of utilities for working with Adobe Flash files (SWF files). The SWFTools version suffers from a buffer overflow vulnerability that stems from a boundary error in the png_read_chunk function when processing png files. An attacker could exploit the vulnerability to trigger a large-scale memory allocation attempt via a specially crafted document.

AI Score

7.2

Confidence

High

EPSS

0

Percentile

12.7%

Related for CNVD-2024-02992