First published: Tue Sep 20 2022(Updated: )
SWFTools commit 772e55a was discovered to contain a heap-use-after-free via the function grow_unicode at /lib/ttf.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Swftools Swftools | =2021-12-16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-40009 is a vulnerability discovered in SWFTools commit 772e55a that allows for a heap-use-after-free attack through the function grow_unicode in the /lib/ttf.c file.
CVE-2022-40009 has a severity rating of 9.8 (Critical).
The SWFTools software version 2021-12-16 is affected by CVE-2022-40009.
To fix CVE-2022-40009, update your SWFTools software to a version that includes the fix for this vulnerability.
You can find more information about CVE-2022-40009 at the following reference link: [https://github.com/matthiaskramm/swftools/issues/190](https://github.com/matthiaskramm/swftools/issues/190).