Package: swftools
Version: 0.9.2+git20130725-4.1
Severity: important
Tags: security, upstream

Upstream bug report: https://github.com/matthiaskramm/swftools/issues/46

CVE description: The swf_DefineLosslessBitsTagToImage function in
lib/modules/swfbits.c in SWFTools 0.9.2 mishandles an uncompress failure, which
allows remote attackers to cause a denial of service (NULL pointer dereference
and application crash) because of extractDefinitions in lib/readers/swf.c and
fill_line_bitmap in lib/devices/render.c, as demonstrated by swfrender.

-- 
Henri Salo

Attachment: signature.asc
Description: PGP signature

Reply via email to