First published: Tue May 31 2022(Updated: )
An issue was discovered in swftools through 20201222. A heap-buffer-overflow exists in the function swf_GetBits() located in rfxswf.c. It allows an attacker to cause code execution.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SWFTools | <=2020-12-22 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-42204 has a high severity rating due to the potential for remote code execution through heap-buffer-overflow.
To fix CVE-2021-42204, update SWFTools to a version released after December 22, 2020.
CVE-2021-42204 affects SWFTools versions up to and including 2020-12-22.
CVE-2021-42204 is classified as a heap-buffer-overflow vulnerability.
Yes, CVE-2021-42204 can be exploited remotely, potentially allowing an attacker to execute arbitrary code.