First published: Wed May 10 2017(Updated: )
A Use After Free in the pdf2swf part of swftools 0.9.2 and earlier allows remote attackers to execute arbitrary code via a malformed PDF document, possibly a consequence of an error in Gfx.cc in Xpdf 3.02.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SWFTools | <=0.9.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7698 is rated as a high severity vulnerability due to its potential to allow remote code execution.
To mitigate CVE-2017-7698, upgrade to a version of SWFTools later than 0.9.2.
Exploitation of CVE-2017-7698 can lead to arbitrary code execution on the affected system.
Users of SWFTools version 0.9.2 and earlier are affected by CVE-2017-7698.
CVE-2017-7698 is classified as a Use After Free vulnerability in the pdf2swf component of SWFTools.