In SWFTools 0.9.2, the wav_convert2mono function in lib/wav.c does not properly restrict a multiplication within a malloc call, which allows remote attackers to cause a denial of service (integer overflow and NULL pointer dereference) via a crafted WAV file.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Swftools | Swftools | 0.9.2 (including) | 0.9.2 (including) |
Swftools | Ubuntu | artful | * |
Swftools | Ubuntu | bionic | * |
Swftools | Ubuntu | cosmic | * |
Swftools | Ubuntu | disco | * |
Swftools | Ubuntu | esm-apps/bionic | * |
Swftools | Ubuntu | esm-apps/xenial | * |
Swftools | Ubuntu | trusty | * |
Swftools | Ubuntu | upstream | * |
Swftools | Ubuntu | xenial | * |
Swftools | Ubuntu | zesty | * |