Loading HuntDB...

GHSA-pqw9-r9pc-pw6x

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

In SWFTools 0.9.2, an out-of-bounds write of heap data can occur in the function png_load() in lib/png.c:755. This issue can be triggered by a malformed PNG file that is mishandled by png2swf. Attackers could exploit this issue for DoS; it might cause arbitrary code execution.

Related CVEs

Key Information

GHSA ID
GHSA-pqw9-r9pc-pw6x
Published
May 17, 2022 2:46 AM
Last Modified
May 17, 2022 2:46 AM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: August 31, 2025 6:33 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.