CVE-2025-6271

A vulnerability, which was classified as problematic, was found in swftools up to 0.9.2. This affects the function wav_convert2mono in the library lib/wav.c of the component wav2swf. The manipulation leads to out-of-bounds read. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.
References
Link Resource
https://github.com/swftools/swftools/issues/239 Exploit Third Party Advisory
https://github.com/user-attachments/files/19415662/wav2swf_crash.txt Exploit
https://vuldb.com/?ctiid.313275 Permissions Required Third Party Advisory VDB Entry
https://vuldb.com/?id.313275 Third Party Advisory VDB Entry
https://vuldb.com/?submit.593005 Third Party Advisory VDB Entry
https://github.com/swftools/swftools/issues/239 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:swftools:swftools:*:*:*:*:*:*:*:*

History

02 Jul 2025, 19:03

Type Values Removed Values Added
CPE cpe:2.3:a:swftools:swftools:*:*:*:*:*:*:*:*
First Time Swftools
Swftools swftools
References () https://github.com/swftools/swftools/issues/239 - () https://github.com/swftools/swftools/issues/239 - Exploit, Third Party Advisory
References () https://github.com/user-attachments/files/19415662/wav2swf_crash.txt - () https://github.com/user-attachments/files/19415662/wav2swf_crash.txt - Exploit
References () https://vuldb.com/?ctiid.313275 - () https://vuldb.com/?ctiid.313275 - Permissions Required, Third Party Advisory, VDB Entry
References () https://vuldb.com/?id.313275 - () https://vuldb.com/?id.313275 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.593005 - () https://vuldb.com/?submit.593005 - Third Party Advisory, VDB Entry

23 Jun 2025, 20:16

Type Values Removed Values Added
References () https://github.com/swftools/swftools/issues/239 - () https://github.com/swftools/swftools/issues/239 -
Summary
  • (es) Se encontró una vulnerabilidad clasificada como problemática en swftools hasta la versión 0.9.2. Esta afecta a la función wav_convert2mono en la librería lib/wav.c del componente wav2swf. La manipulación provoca lecturas fuera de los límites. El ataque debe abordarse localmente. Se ha hecho público el exploit y puede que sea utilizado.

19 Jun 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-19 18:15

Updated : 2025-07-02 19:03


NVD link : CVE-2025-6271

Mitre link : CVE-2025-6271

CVE.ORG link : CVE-2025-6271


JSON object : View

Products Affected

swftools

  • swftools
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-125

Out-of-bounds Read