CVE-2025-26307: Medium severity Libming Libming vulnerability
Published Feb 20, 2025
·Updated
A memory leak has been identified in the parseSWFIMPORTASSETS2 function in util/parser.c of libming v0.4.8, which allows attackers to cause a denial of service via a crafted SWF file.
Affected Software
2 affected components
Libming Libming
Libming Libming=0.4.8
Event History
Feb 20, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-26307?
CVE-2025-26307 is classified as a moderate severity vulnerability due to its potential for causing denial of service.
2
How do I fix CVE-2025-26307?
To fix CVE-2025-26307, you should upgrade to the latest version of libming that addresses the memory leak issue.
3
What type of application is affected by CVE-2025-26307?
CVE-2025-26307 affects applications that utilize the libming library for parsing SWF files.
4
What exploitation impact does CVE-2025-26307 have?
Exploiting CVE-2025-26307 can lead to a denial of service by consuming memory resources through specially crafted SWF files.
5
Who is the vendor for CVE-2025-26307?
The vendor for CVE-2025-26307 is libming, an open-source project used for handling SWF file manipulation.