Heap Use After Free Vulnerability in swftools by Matthias Kramm
CVE-2021-42203

7.8HIGH

Key Information:

Vendor

Swftools

Status
Vendor
CVE Published:
2 June 2022

What is CVE-2021-42203?

A heap-use-after-free vulnerability has been identified in swftools, specifically within the function swf_FontExtract_DefineTextCallback() in swftext.c. This issue can be leveraged by attackers to execute arbitrary code, potentially compromising the integrity of the affected systems. Users of vulnerable versions should take immediate action to evaluate their exposure and implement necessary security measures.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.