First published: Tue Sep 20 2022(Updated: )
SWFTools commit 772e55a was discovered to contain a heap-buffer overflow via the function readU8 at /lib/ttf.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Swftools Swftools | =2021-12-16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-40008 is a heap-buffer overflow vulnerability discovered in SWFTools commit 772e55a.
CVE-2022-40008 has a severity rating of 9.8, which is considered critical.
SWFTools version 2021-12-16 is affected by CVE-2022-40008.
CVE-2022-40008 is classified under CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) and CWE-787 (Out-of-bounds Write).
Yes, you can find more information about CVE-2022-40008 in the following link: [GitHub issue #188](https://github.com/matthiaskramm/swftools/issues/188)