CVE-2025-6271
low
CVSS v3
3.3
CVSS v2
1.7
VIR risk
3.3
Description
A vulnerability, which was classified as problematic, was found in swftools up to 0.9.2. This affects the function wav_convert2mono in the library lib/wav.c of the component wav2swf. The manipulation leads to out-of-bounds read. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.
Predictions
Exploit likelihood
34%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| swftools | swftools | {"endExcluding":"0.9.2"} | 0.9.2 |
References
CWEs
CWE-119 CWE-125
Verify integrity in audit chain (admin only). AS-IS.