PT-2017-18523 · Libming · Libming

Published

2017-05-31

·

Updated

2018-04-30

·

CVE-2017-8782

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libming version 0.4.8
Description The issue is related to the readString function in util/read.c and util/old/read.c, which can be exploited by remote attackers to cause a denial of service. This happens when a large file is mishandled by tools like listswf or listaction, leading to an integer overflow and subsequent memory allocation error.
Recommendations For libming version 0.4.8, consider applying a patch or fix that addresses the integer overflow in the readString function to prevent denial of service attacks.

Exploit

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-8782
DLA-980-1
MGASA-2018-0212

Affected Products

Libming