First published: Thu Jan 06 2022(Updated: )
In libming 0.4.8, the parseSWF_DEFINELOSSLESS2 function in util/parser.c lacks a boundary check that would lead to denial-of-service attacks via a crafted SWF file.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Libming Libming | =0.4.8 | |
=0.4.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-44591 is a vulnerability in libming 0.4.8 that allows denial-of-service attacks via a crafted SWF file.
The severity of CVE-2021-44591 is medium, with a CVSS score of 6.5.
CVE-2021-44591 affects libming 0.4.8.
CVE-2021-44591 can be exploited by using a crafted SWF file.
Yes, updating to a version of libming that is not affected by CVE-2021-44591 resolves this vulnerability.