First published: Fri Sep 23 2022(Updated: )
SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via GfxICCBasedColorSpace::getDefaultColor(GfxColor*) at /xpdf/GfxState.cc.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SWFTools | =2021-12-16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-35098 is classified as a high severity vulnerability due to its potential to cause a heap-buffer overflow.
To remediate CVE-2022-35098, it is recommended to update to a patched version of SWFTools that addresses the heap-buffer overflow issue.
The potential impacts of CVE-2022-35098 include system crashes or arbitrary code execution stemming from the heap-buffer overflow.
CVE-2022-35098 affects the SWFTools version 2021-12-16.
You can determine if your system is vulnerable to CVE-2022-35098 by checking if you are using the affected version of SWFTools and reviewing if any patches are applied.