CVE-2025-29487

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Mar 27, 2025
Updated: Apr 1, 2025
CWE ID 400

Summary

CVE-2025-29487 is a Denial of Service vulnerability affecting libming v0.4.8. The issue lies in the parseABC_STRING_INFO function, where an out-of-memory error occurs. Attackers can exploit this flaw to trigger allocator exhaustion, resulting in a Denial of Service condition. The vulnerability does not allow for remote code execution or data exfiltration, but it can cause significant disruptions to services relying on the affected library. Users are advised to update to a patched version of libming to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share