PT-2025-13250 · Libming · Libming

Published

2025-03-27

·

Updated

2025-03-29

·

CVE-2025-29491

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libming version 0.48
Description The issue is related to an allocation-size-too-big error in the parseSWF DEFINEBINARYDATA function, which allows attackers to cause a Denial of Service (DoS) by supplying a crafted SWF file.
Recommendations For libming version 0.48, consider disabling the parseSWF DEFINEBINARYDATA function as a temporary workaround until a patch is available. Restrict the processing of SWF files from untrusted sources to minimize the risk of exploitation.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-29491

Affected Products

Libming