CVE-2025-29488

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Mar 27, 2025
Updated: Apr 1, 2025
CWE ID 200

Summary

CVE-2025-29488 is a newly identified vulnerability affecting libming version 0.4.8. This issue involves a memory leak in the parseSWF_INITACTION function, which could potentially be exploited by malicious actors to execute arbitrary code or cause a denial-of-service condition. An attacker could trigger this vulnerability by providing specially crafted SWF files to the application using libming. Successful exploitation of this flaw could result in serious consequences, including data theft or system compromise. To mitigate this risk, users are advised to upgrade to the latest version of libming or consider alternative libraries to handle SWF files.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share