Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gjjr-423g-hm3j

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

In SWFTools 0.9.2, the wav_convert2mono function in lib/wav.c does not properly restrict a multiplication within a malloc call, which allows remote attackers to cause a denial of service (integer overflow and NULL pointer dereference) via a crafted WAV file.

In SWFTools 0.9.2, the wav_convert2mono function in lib/wav.c does not properly restrict a multiplication within a malloc call, which allows remote attackers to cause a denial of service (integer overflow and NULL pointer dereference) via a crafted WAV file.

EPSS

Процентиль: 41%
0.00189
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-476

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 8 лет назад

In SWFTools 0.9.2, the wav_convert2mono function in lib/wav.c does not properly restrict a multiplication within a malloc call, which allows remote attackers to cause a denial of service (integer overflow and NULL pointer dereference) via a crafted WAV file.

CVSS3: 5.5
nvd
около 8 лет назад

In SWFTools 0.9.2, the wav_convert2mono function in lib/wav.c does not properly restrict a multiplication within a malloc call, which allows remote attackers to cause a denial of service (integer overflow and NULL pointer dereference) via a crafted WAV file.

CVSS3: 5.5
debian
около 8 лет назад

In SWFTools 0.9.2, the wav_convert2mono function in lib/wav.c does not ...

EPSS

Процентиль: 41%
0.00189
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-476