First published: Wed Jul 05 2017(Updated: )
SWFTools 2013-04-09-1007 on Windows has a "Data from Faulting Address controls Branch Selection starting at image00000000_00400000+0x0000000000003e71" issue. This issue can be triggered by a malformed TTF file that is mishandled by font2swf. Attackers could exploit this issue for DoS (Access Violation).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SWFTools | =2013-04-09-1007 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8420 has a severity rating that indicates a potential denial of service vulnerability.
To remediate CVE-2017-8420, avoid using SWFTools 2013-04-09-1007 with untrusted TTF files.
CVE-2017-8420 can lead to denial of service attacks due to mishandling of malformed TTF files.
CVE-2017-8420 specifically affects SWFTools version 2013-04-09-1007 on Windows.
CVE-2017-8420 can potentially be exploited locally by delivering a malformed TTF file to the affected software.