Mageia alert MGASA-2017-0245 (swftools)
From: | Mageia Updates <buildsystem-daemon@mageia.org> | |
To: | updates-announce@ml.mageia.org | |
Subject: | [updates-announce] MGASA-2017-0245: Updated swftools package fixes security vulnerability | |
Date: | Tue, 8 Aug 2017 00:16:59 +0200 | |
Message-ID: | <20170807221659.DC8E79F877@duvel.mageia.org> |
MGASA-2017-0245 - Updated swftools package fixes security vulnerability Publication date: 07 Aug 2017 URL: http://advisories.mageia.org/MGASA-2017-0245.html Type: security Affected Mageia releases: 5 CVE: CVE-2017-8400 Description: In SWFTools 0.9.2, an out-of-bounds write of heap data can occur in the function png_load() in lib/png.c. This issue can be triggered by a malformed PNG file that is mishandled by png2swf. Attackers could exploit this issue for DoS; it might cause arbitrary code execution (CVE-2017-8400). References: - https://bugs.mageia.org/show_bug.cgi?id=20846 - https://lists.opensuse.org/opensuse-updates/2017-05/msg00... - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8400 SRPMS: - 5/core/swftools-0.9.2-7.1.mga5