Null Pointer Dereference in SWFTools Affects Multiple Applications
CVE-2024-28458

Currently unrated

Key Information:

Vendor

SWFTools

Status
Vendor
CVE Published:
11 April 2024

What is CVE-2024-28458?

A vulnerability exists in the SWFTools application, specifically in the swfdump utility, version 0.9.2. This flaw, characterized as a Null Pointer Dereference, occurs in the compileSWFActionCode function located in action/actioncompiler.c. An attacker can exploit this weakness to trigger an unexpected application crash, potentially leading to denial-of-service scenarios. Users of SWFTools are encouraged to assess their environments for this vulnerability and consider applying any available patches or mitigating measures.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.