CVE-2017-16793: Swftools

High severity, CVSS 7.8. EPSS: 1.2% chance of exploitation in the next 30 days.

The wav_convert2mono function in lib/wav.c in SWFTools 0.9.2 does not properly validate WAV data, which allows remote attackers to cause a denial of service (incorrect malloc and heap-based buffer overflow) or possibly have unspecified other impact via a crafted file.

Affected products

Published 2017-11-12. Last modified 2026-06-17.