CVE-2017-16868: Swftools
Medium severity, CVSS 5.5. EPSS: 1.1% chance of exploitation in the next 30 days.
In SWFTools 0.9.2, the wav_convert2mono function in lib/wav.c does not properly restrict a multiplication within a malloc call, which allows remote attackers to cause a denial of service (integer overflow and NULL pointer dereference) via a crafted WAV file.
Affected products
- Swftools Swftools: version 0.9.2 only
Published 2017-11-17. Last modified 2026-06-17.