Heap Buffer Overflow in swftools Affects Code Execution
CVE-2021-39564

7.8HIGH

Key Information:

Vendor

Swftools

Status
Vendor
CVE Published:
20 September 2021

What is CVE-2021-39564?

A vulnerability in swftools allows a heap-buffer-overflow in the swf_DumpActions() function, potentially leading to unauthorized code execution. This issue affects all versions up to 20200710, posing a significant risk for users who have not updated. Attackers could exploit this vulnerability to execute arbitrary code, highlighting the necessity for timely software updates and security patches.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.