CVE-2025-26308
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Feb 20, 2025
Updated: Feb 24, 2025
CWE ID 401
Summary
CVE-2025-26308 is a denial-of-service vulnerability affecting libming v0.4.8. The issue lies in the parseSWF_FILTERLIST function within util/parser.c, where a memory leak occurs. Attackers can exploit this flaw by supplying a maliciously crafted SWF file to trigger the memory leak and cause the system to become unresponsive or crash. This vulnerability poses a significant risk, particularly in environments where users frequently interact with SWF files, and requires immediate attention from system administrators to apply the available patch.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share