CVE-2021-42203

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
02/06/2022
Last modified:
08/06/2022

Description

An issue was discovered in swftools through 20201222. A heap-use-after-free exists in the function swf_FontExtract_DefineTextCallback() located in swftext.c. It allows an attacker to cause code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:swftools:swftools:*:*:*:*:*:*:*:* 2020-12-22 (including)


References to Advisories, Solutions, and Tools