CVE-2025-26311
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Feb 20, 2025
CWE ID 401
Summary
CVE-2025-26311 is a denial-of-service vulnerability affecting libming v0.4.8. The issue lies in the clip actions parsing functions (parseSWF_CLIPACTIONS and parseSWF_CLIPACTIONRECORD) in util/parser.c. Multiple memory leaks have been discovered in these functions, which can be exploited by attackers through a specially crafted SWF file. The memory leaks result in excessive memory consumption, leading to a denial-of-service condition. Upgrading to a patched version of libming is recommended to mitigate this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share