swftools wav2swf wav.c wav_convert2mono out-of-bounds

CVE Details

Basic Information

Title swftools wav2swf wav.c wav_convert2mono out-of-bounds
Type cve
Published 2025-06-19T17:31:06.353Z
Last Seen

Product Information

Vendor n/a
Product swftools
Version 0.9.0

CVSS Information

Base Score 4.8 (MEDIUM)
Attack Vector CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
Confidentiality Impact
Integrity Impact
Availability Impact

AI Analysis

AI Description A vulnerability in swftools’ wav_convert2mono function allows an out-of-bounds read, potentially leading to crashes or information leaks. This issue affects versions up to 0.9.2 and requires local access to exploit.
AI Severity Medium
Vendor swftools community
Product swftools
Affected Version 0.9.0, 0.9.1, 0.9.2

Affected Products

  • n/a swftools 0.9.0
  • n/a swftools 0.9.1
  • n/a swftools 0.9.2

Additional Information

CVE List
CWE List CWE-125, CWE-119
Bulletin Family

Description

A vulnerability, which was classified as problematic, was found in swftools up to 0.9.2. This affects the function wav_convert2mono in the library lib/wav.c of the component wav2swf. The manipulation leads to out-of-bounds read. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.