CVE-2020-11895: Critical severity libming vulnerability
Published Apr 19, 2020
·Updated
Ming (aka libming) 0.4.8 has a heap-based buffer over-read (2 bytes) in the function decompileIF() in decompile.c.
Affected Software
1 affected component
Libming Libming=0.4.8
Event History
Apr 19, 2020
CVE Published
via MITRE·06:04 PM
Data Sourced
via MITRE·06:04 PM
Description
Frequently Asked Questions
1
What is CVE-2020-11895?
CVE-2020-11895 is a vulnerability in Ming (aka libming) 0.4.8 that allows a heap-based buffer over-read in the function decompileIF() in decompile.c.
2
How severe is CVE-2020-11895?
CVE-2020-11895 has a severity rating of 9.1 (critical).
3
What software versions are affected by CVE-2020-11895?
Ming (aka libming) version 0.4.8 is affected by CVE-2020-11895.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-11895?
CVE-2020-11895 is associated with CWE-125 (Out-of-bounds Read).
5
Is there a fix for CVE-2020-11895?
At the time of writing, there is no known fix or patch available for CVE-2020-11895. It is recommended to apply any official updates or patches from the software vendor if and when they become available.