Stack Buffer Underflow in swftools by Matthiaskramm
CVE-2024-22562

7.8HIGH

Key Information:

Vendor

Swftools

Vendor
CVE Published:
19 January 2024

What is CVE-2024-22562?

The vulnerability identified in swftools version 0.9.2 involves a stack buffer underflow in the function dict_foreach_keyvalue located at swftools/lib/q.c. This flaw may allow attackers to manipulate memory allocation, potentially leading to arbitrary code execution or data leakage. It is crucial for users and administrators of swftools to evaluate their systems and consider necessary updates or safeguards to mitigate potential exploitation.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.