PT-2017-12207 · Ming · Ming
Published
2017-07-29
·
Updated
2019-10-03
·
CVE-2017-11730
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Ming version 0.4.8
Description
A heap-based buffer over-read was found in the function OpCode, which is called from decompileINCR DECR line 1474 in util/decompile.c. This issue allows attackers to cause a denial of service via a crafted file.
Recommendations
For Ming version 0.4.8, consider avoiding the use of crafted files that may trigger the denial of service until a patch is available. As a temporary workaround, restrict access to the decompileINCR DECR function to minimize the risk of exploitation.
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ming