PT-2017-12207 · Ming · Ming

Published

2017-07-29

·

Updated

2019-10-03

·

CVE-2017-11730

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Ming version 0.4.8
Description A heap-based buffer over-read was found in the function OpCode, which is called from decompileINCR DECR line 1474 in util/decompile.c. This issue allows attackers to cause a denial of service via a crafted file.
Recommendations For Ming version 0.4.8, consider avoiding the use of crafted files that may trigger the denial of service until a patch is available. As a temporary workaround, restrict access to the decompileINCR DECR function to minimize the risk of exploitation.

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-11730
DLA-1133-1
MGASA-2018-0212

Affected Products

Ming