Vulnerability Description
A Use After Free in the pdf2swf part of swftools 0.9.2 and earlier allows remote attackers to execute arbitrary code via a malformed PDF document, possibly a consequence of an error in Gfx.cc in Xpdf 3.02.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Swftools | Swftools | <= 0.9.2 |
Related Weaknesses (CWE)
References
- https://github.com/matthiaskramm/swftools/pull/19Issue TrackingPatchThird Party Advisory
- https://github.com/matthiaskramm/swftools/pull/19Issue TrackingPatchThird Party Advisory
FAQ
What is CVE-2017-7698?
CVE-2017-7698 is a vulnerability with a CVSS score of 7.8 (HIGH). A Use After Free in the pdf2swf part of swftools 0.9.2 and earlier allows remote attackers to execute arbitrary code via a malformed PDF document, possibly a consequence of an error in Gfx.cc in Xpdf ...
How severe is CVE-2017-7698?
CVE-2017-7698 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-7698?
Check the references section above for vendor advisories and patch information. Affected products include: Swftools Swftools.