PT-2022-12179 · Libming · Libming

0Xdd96

·

Published

2022-01-06

·

Updated

2022-01-13

·

CVE-2021-44591

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libming version 0.4.8
Description The issue is related to a lack of boundary check in the parseSWF DEFINELOSSLESS2 function, located in util/parser.c, which could lead to denial-of-service attacks via a crafted SWF file.
Recommendations For libming version 0.4.8, consider applying a patch or fix that adds a boundary check to the parseSWF DEFINELOSSLESS2 function to prevent denial-of-service attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-44591

Affected Products

Libming