Heap Use-After-Free Vulnerability in SWFTools by Matthias Kramm
CVE-2022-40009
9.8CRITICAL
What is CVE-2022-40009?
A heap-use-after-free vulnerability has been identified in SWFTools due to a flaw in the function grow_unicode located in lib/ttf.c. An attacker can exploit this vulnerability to cause unexpected behavior in the software, potentially leading to code execution or data corruption.