Heap Buffer Overflow in SWFDump Affects Multiple Versions
CVE-2023-27249

5.5MEDIUM

Key Information:

Vendor

Swftools

Status
Vendor
CVE Published:
23 March 2023

What is CVE-2023-27249?

SWFDump version 0.9.2 has been identified to have a heap buffer overflow vulnerability in the swf_GetPlaceObject function located in swfobject.c. This flaw can lead to unexpected behavior in the software, potentially allowing an attacker to exploit the overflow condition, which may result in code execution or system compromise. Users of SWFDump are advised to review their software versions and apply necessary patches.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.