CVE-2023-37644: Swftools
Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.
SWFTools 0.9.2 772e55a allows attackers to trigger a large memory-allocation attempt via a crafted document, as demonstrated by pdf2swf. This occurs in png_read_chunk in lib/png.c.
Affected products
- Swftools Swftools: version 0.9.2 only
Published 2024-01-11. Last modified 2026-06-17.