HIGH
In SWFTools 0.9.2, the png_load function in lib/png.c does not properly validate an alloclen_64 multiplication of width and height values, which allows remote attackers to cause a denial of service (integer overflow, heap-based buffer overflow, and application crash) or possibly have unspecified other impact via a crafted PNG file
Published Nov 12, 2017
7.8
HIGHCVSS 3.0
EPSS 1.24%
Description
Affected products
Remediation
Metrics
References (1)
Change history (0)
No recorded changes yet.