CVE-2017-8400 In SWFTools 0.9.2, an out-of-bounds write of heap data can occur in the function png_load() in lib/png.c:755. This issue can be triggered by a malformed PNG file that is mishandled by png2swf. . Hash: SHA512 Package : swftools Version : 0.9.2+ds1-3+deb7u1 CVE ID : CVE-2017-8400 CVE-2017-8401 CVE-2017-8400 In SWFTools 0.9.2, an out-of-bounds write of heap data can occur in the function png_load() in lib/png.c:755. This issue can be triggered by a malformed PNG file that is mishandled by png2swf. Attackers could exploit this issue for DoS; it might cause arbitrary code execution. CVE-2017-8401 In SWFTools 0.9.2, an out-of-bounds read of heap data can occur in the function png_load() in lib/png.c:724. This issue can be triggered by a malformed PNG file that is mishandled by png2swf. Attackers could exploit this issue for DoS. For Debian 7 "Wheezy", these problems have been fixed in version 0.9.2+ds1-3+deb7u1. We recommend that you upgrade your swftools packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance swftools on Debian 7 to address severe out-of-bounds vulnerabilities which may result in Denial of Service or the potential for arbitrary code execution threats.. Debian Swftools Security, Heap Corruption Update, DoS Threats Fix. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.