Hash: SHA512

Package        : swftools
Version        : 0.9.2+ds1-3+deb7u1
CVE ID         : CVE-2017-8400 CVE-2017-8401

CVE-2017-8400
      In SWFTools 0.9.2, an out-of-bounds write of heap data can occur in
      the function png_load() in lib/png.c:755. This issue can be triggered
      by a malformed PNG file that is mishandled by png2swf.
      Attackers could exploit this issue for DoS; it might cause arbitrary
      code execution.

CVE-2017-8401
      In SWFTools 0.9.2, an out-of-bounds read of heap data can occur in
      the function png_load() in lib/png.c:724. This issue can be triggered
      by a malformed PNG file that is mishandled by png2swf.
      Attackers could exploit this issue for DoS.


For Debian 7 "Wheezy", these problems have been fixed in version
0.9.2+ds1-3+deb7u1.

We recommend that you upgrade your swftools packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Debian LTS: DLA-995-1: swftools security update

June 20, 2017
CVE-2017-8400 In SWFTools 0.9.2, an out-of-bounds write of heap data can occur in the function png_load() in lib/png.c:755

Summary

CVE-2017-8401
In SWFTools 0.9.2, an out-of-bounds read of heap data can occur in
the function png_load() in lib/png.c:724. This issue can be triggered
by a malformed PNG file that is mishandled by png2swf.
Attackers could exploit this issue for DoS.


For Debian 7 "Wheezy", these problems have been fixed in version
0.9.2+ds1-3+deb7u1.

We recommend that you upgrade your swftools packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



Severity
Package : swftools
Version : 0.9.2+ds1-3+deb7u1
CVE ID : CVE-2017-8400 CVE-2017-8401

Related News