CVE-2017-7578: Buffer Overflow
Multiple heap-based buffer overflows in parser.c in libming 0.4.7 allow remote attackers to cause a denial of service (listswf application crash) or possibly have unspecified other impact via a crafted SWF file. NOTE: this issue exists because of an incomplete fix for CVE-2016-9831.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
libmingto a version that resolves this vulnerability.Fixed in 0.4.7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2016-9831
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7578?
The severity of CVE-2017-7578 is regarded as high due to the potential for denial of service and crashes in the listswf application.
What causes CVE-2017-7578?
CVE-2017-7578 is caused by multiple heap-based buffer overflows in the parser.c file of libming version 0.4.7.
How do I fix CVE-2017-7578?
Fix CVE-2017-7578 by upgrading to a more recent version of libming that has addressed this vulnerability.
Which versions of libming are affected by CVE-2017-7578?
CVE-2017-7578 affects libming version 0.4.7.
What could be the impact of exploiting CVE-2017-7578?
Exploiting CVE-2017-7578 could lead to denial of service through application crashes, and potentially other unspecified impacts.