First published: Thu Feb 20 2025(Updated: )
A memory leak has been identified in the parseSWF_SOUNDINFO function in util/parser.c of libming v0.4.8, which allows attackers to cause a denial of service via a crafted SWF file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Libming |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-26305 is classified as a denial of service vulnerability due to a memory leak in the libming library.
To mitigate CVE-2025-26305, update to the latest version of libming that addresses the memory leak issue.
CVE-2025-26305 is caused by improper handling of SWF files in the parseSWF_SOUNDINFO function.
CVE-2025-26305 affects libming version 0.4.8 and potentially earlier versions.
Yes, CVE-2025-26305 can be exploited remotely through specially crafted SWF files.