CVE-2017-16793: Swftools
High severity, CVSS 7.8. EPSS: 1.2% chance of exploitation in the next 30 days.
The wav_convert2mono function in lib/wav.c in SWFTools 0.9.2 does not properly validate WAV data, which allows remote attackers to cause a denial of service (incorrect malloc and heap-based buffer overflow) or possibly have unspecified other impact via a crafted file.
Affected products
- Swftools Swftools: version 0.9.2 only
Published 2017-11-12. Last modified 2026-06-17.