Vulnerabilities > CVE-2017-16868 - NULL Pointer Dereference vulnerability in Swftools 0.9.2

047910
CVSS 5.5 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
local
low complexity
swftools
CWE-476

Summary

In SWFTools 0.9.2, the wav_convert2mono function in lib/wav.c does not properly restrict a multiplication within a malloc call, which allows remote attackers to cause a denial of service (integer overflow and NULL pointer dereference) via a crafted WAV file.

Vulnerable Configurations

Part Description Count
Application
Swftools
1

Common Weakness Enumeration (CWE)