Generate or decompile Adobe Flash SWF files using an XML dialect. Inspect and modify the XML by hand, or by using a built in XSLT processor.
GNU General Public License v2.0
131
stars
28
forks
source link
bug3: an interger overflow in swfmill swf2xml #48
Open
ghost opened 6 years ago
poc: https://drive.google.com/open?id=1Z8WmeSap9iPaiUcVJZCIfrkZfvHUSOSa asan: https://drive.google.com/open?id=1v47arABbjZFQyRV_8lSBOT59jKuTW8gT
swfmill/src/SWFReader.cpp the segmentfault happens at
uint32_t len is from getU30(); in this function there exists an interger overflow
r will be 0xffffffff after parsing.