CVE-2025-29488
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2025-29488 is a newly identified vulnerability affecting libming version 0.4.8. This issue involves a memory leak in the parseSWF_INITACTION function, which could potentially be exploited by malicious actors to execute arbitrary code or cause a denial-of-service condition. An attacker could trigger this vulnerability by providing specially crafted SWF files to the application using libming. Successful exploitation of this flaw could result in serious consequences, including data theft or system compromise. To mitigate this risk, users are advised to upgrade to the latest version of libming or consider alternative libraries to handle SWF files.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.