The readEncUInt30 function in util/read.c in libming 0.4.8 mishandles memory allocation. A crafted input will lead to a remote denial of service (NULL pointer dereference) attack against parser.c.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/libming/libming/issues/85 | Exploit Third Party Advisory | 
| https://lists.debian.org/debian-lts-announce/2017/11/msg00022.html | Mailing List Third Party Advisory | 
| https://security.gentoo.org/glsa/201904-24 | Third Party Advisory | 
| https://github.com/libming/libming/issues/85 | Exploit Third Party Advisory | 
| https://lists.debian.org/debian-lts-announce/2017/11/msg00022.html | Mailing List Third Party Advisory | 
| https://security.gentoo.org/glsa/201904-24 | Third Party Advisory | 
Configurations
                    History
                    No history.
Information
                Published : 2017-06-28 06:29
Updated : 2025-04-20 01:37
NVD link : CVE-2017-9988
Mitre link : CVE-2017-9988
CVE.ORG link : CVE-2017-9988
JSON object : View
Products Affected
                libming
- libming
 
debian
- debian_linux
 
CWE
                
                    
                        
                        CWE-476
                        
            NULL Pointer Dereference
