Lucene search

K
ubuntucveUbuntu.comUB:CVE-2010-1516
HistoryAug 17, 2010 - 12:00 a.m.

CVE-2010-1516

2010-08-1700:00:00
ubuntu.com
ubuntu.com
8

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.024

Percentile

89.9%

Multiple integer overflows in SWFTools 0.9.1 allow remote attackers to
execute arbitrary code via (1) a crafted PNG file, related to the getPNG
function in lib/png.c; or (2) a crafted JPEG file, related to the jpeg_load
function in lib/jpeg.c.

Notes

Author Note
mdeslaur ignoring this, upstream needs to fix in partner.

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.024

Percentile

89.9%