First published: Fri Jan 19 2024(Updated: )
A heap-use-after-free was found in SWFTools v0.9.2, in the function swf_DeleteTag at rfxswf.c:1193. It allows an attacker to cause code execution.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SWFTools | =0.9.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-22915 is classified as a high severity vulnerability due to its potential to allow code execution.
To fix CVE-2024-22915, upgrade SWFTools to the latest version that addresses this specific vulnerability.
CVE-2024-22915 can enable attackers to execute arbitrary code by exploiting the heap-use-after-free condition.
CVE-2024-22915 specifically affects SWFTools version 0.9.2.
Yes, CVE-2024-22915 can potentially be exploited remotely if an attacker can induce the vulnerable software to process malicious input.