C’è una perdita di memoria in util / parser.c in libming 0.4.8, che porterà ad una negazione di servizio via parseSWF_DEFINEBUTTON2, parseSWF_DEFINEFONT, parseSWF_DEFINEFONTINFO, parseSWF_DEFINELOSSLESS, parseSWF_DEFINESPRITE, parseSWF_DEFINETEXT, parseSWF_DOACTION, parseSWF_FILLSTYLEARRAY, parseSWF_FRAMELABEL, parseSWF_LINESTYLEARRAY, parseSWF_PLACEOBJECT2 o parseSWF_SHAPEWITHSTYLE . |
https://github.com/libming/libming/issues/146 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-13066 |
Vulnerabilità: CVE-2018-13066
