PT-2022-12178 · Libming · Libming

0Xdd96

·

Published

2022-01-06

·

Updated

2022-07-12

·

CVE-2021-44590

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libming version 0.4.8
Description A memory exhaustion issue exists in the function cws2fws in util/main.c, allowing remote attackers to launch denial of service attacks by submitting a crafted SWF file.
Recommendations For libming version 0.4.8, consider restricting the submission of SWF files or limiting the resources available to the cws2fws function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-44590

Affected Products

Libming