First published: Fri Sep 23 2022(Updated: )
SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via DCTStream::readHuffSym(DCTHuffTable*) at /xpdf/Stream.cc.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SWFTools | =2021-12-16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-35094 is classified as a high-severity vulnerability due to the potential for exploitation through heap-buffer overflow.
CVE-2022-35094 impacts SWFTools versions 2021-12-16 by allowing attackers to cause a heap-buffer overflow, leading to potential arbitrary code execution.
To fix CVE-2022-35094, users should update to the latest patched version of SWFTools that addresses this vulnerability.
In CVE-2022-35094, the heap-buffer overflow occurs in the readHuffSym function, potentially allowing the manipulation of memory and execution of malicious code.
As of now, there is no publicly available information indicating that CVE-2022-35094 is actively being exploited in the wild.