First published: Thu Jan 11 2024(Updated: )
SWFTools 0.9.2 772e55a allows attackers to trigger a large memory-allocation attempt via a crafted document, as demonstrated by pdf2swf. This occurs in png_read_chunk in lib/png.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SWFTools | =0.9.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-37644 is classified as moderate due to potential denial of service risks.
To fix CVE-2023-37644, upgrade to a newer version of SWFTools that addresses this vulnerability.
CVE-2023-37644 can be exploited by sending a specially crafted document to trigger excessive memory allocation in SWFTools.
CVE-2023-37644 affects the png_read_chunk function in the lib/png.c component of SWFTools.
CVE-2023-37644 is specifically known to affect version 0.9.2 of SWFTools.