Global Buffer Overflow Vulnerability in Swftools Software
CVE-2024-22919

7.8HIGH

Key Information:

Vendor

Swftools

Vendor
CVE Published:
19 January 2024

What is CVE-2024-22919?

A global buffer overflow vulnerability has been identified in Swftools version 0.9.2, specifically in the parseExpression function located at swftools/src/swfc.c:2587. This vulnerability could be exploited by an attacker to overwrite adjacent memory, potentially leading to arbitrary code execution or causing a denial of service. Users are advised to review the issue and apply any necessary patches or updates to safeguard against potential exploitation.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.