First published: Tue Aug 17 2010(Updated: )
Multiple integer overflows in SWFTools 0.9.1 allow remote attackers to execute arbitrary code via (1) a crafted PNG file, related to the getPNG function in lib/png.c; or (2) a crafted JPEG file, related to the jpeg_load function in lib/jpeg.c.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
SWFTools SWFTools | =0.9.1 | |
SWFTools | =0.9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-1516 has a medium to high severity rating due to the potential for remote code execution.
To mitigate CVE-2010-1516, upgrade to a newer version of SWFTools that addresses this vulnerability.
CVE-2010-1516 can allow attackers to execute arbitrary code on your system through specially crafted PNG or JPEG files.
Yes, CVE-2010-1516 can be exploited remotely if a malicious user sends a crafted image file to an unpatched system.
SWFTools 0.9.1 is specifically mentioned as the affected version for CVE-2010-1516, so using any version later than this could mitigate the risk.