The outputSWF_TEXT_RECORD function in util/outputscript.c in libming <= 0.4.8 is vulnerable to a NULL pointer dereference, which may allow attackers to cause a denial of service via a crafted swf file.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
https://lists.debian.org/debian-lts-announce/2018/01/msg00014.html | mailing list |
https://github.com/libming/libming/issues/77 | issue tracking vendor advisory |