MEDIUM
The pushdup function in util/decompile.c in libming through 0.4.8 does not recognize the need for ActionPushDuplicate to perform a deep copy when a String is at the top of the stack, making the library vulnerable to a util/decompile.c getName NULL pointer dereference, which may allow attackers to cause a denial of service via a crafted SWF file
Published Apr 1, 2018
6.5
MEDIUMCVSS 3.0
EPSS 1.10%
Description
Affected products
Remediation
Metrics
References (2)
Change history (0)
No recorded changes yet.