CVE-2017-16868: Swftools

Medium severity, CVSS 5.5. EPSS: 1.1% chance of exploitation in the next 30 days.

In SWFTools 0.9.2, the wav_convert2mono function in lib/wav.c does not properly restrict a multiplication within a malloc call, which allows remote attackers to cause a denial of service (integer overflow and NULL pointer dereference) via a crafted WAV file.

Affected products

Published 2017-11-17. Last modified 2026-06-17.