CVE-2025-26307

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Feb 20, 2025
Updated: Feb 21, 2025
CWE ID 401

Summary

CVE-2025-26307 is a denial-of-service vulnerability affecting the parseSWF_IMPORTASSETS2 function in libming v0.4.8's util/parser.c. The issue arises from a memory leak in this function, which can be exploited by attackers to cause excessive memory consumption. By providing a specially crafted SWF file, they can induce the software to allocate and leak memory, eventually leading to a system crash or unresponsiveness. This vulnerability poses a significant risk, particularly in environments where users are exposed to untrusted SWF files, and requires immediate patching to prevent potential disruptions.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share