PT-2025-7601 · Libming · Libming

Xuhxxo

·

Published

2025-02-20

·

Updated

2025-02-24

·

CVE-2025-26310

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libming version 0.4.8
Description Multiple memory leaks have been identified in the ABC file parsing functions, specifically in parseABC CONSTANT POOL and parseABC FILE, which allow attackers to cause a denial of service via a crafted ABC file. The issue is related to the util/parser.c file in libming.
Recommendations For libming version 0.4.8, consider disabling the parseABC CONSTANT POOL and parseABC FILE functions as a temporary workaround to prevent potential denial of service attacks until a patch is available. Restrict access to the vulnerable util/parser.c module to minimize the risk of exploitation. Avoid using crafted ABC files that could trigger the memory leaks in the affected functions. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-26310

Affected Products

Libming