Description
An issue in libming through 0.4.8 allows a remote attacker to cause a denial of service via the readtag_file() in src/blocks/fromswf.c.
Published: 2026-10-08
Score: n/a
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Assess Impact
AI Analysis

Impact

A flaw in libming versions up to 0.4.8 allows a remote attacker to trigger a crash by sending a crafted SWF file that exploits the readtag_file() routine in src/blocks/fromswf.c. The crash results in an application or service termination, thereby denying legitimate users from accessing the affected functionality. The underlying weakness can be classified as an improper handling of input that leads to a buffer overrun or out‑of‑bounds access, which in this case causes a denial of service. No further features such as code execution or privilege escalation are disclosed or implied by the current description.

Affected Systems

The vulnerability affects any installation that relies on libming 0.4.8 or older. Systems using this library to process SWF files—such as editors, converters or embedded rendering engines—are potentially impacted. Exact product names are not specified, but any software bundling the vulnerable libming release is at risk.

Risk and Exploitability

The likely attack vector is remote, as the flaw is triggered by a maliciously crafted SWF file that an attacker can supply to a vulnerable application. The exploit requires no authentication or privileged access; the user only needs to cause the application to parse the malicious file. EPSS information is not available, and the flaw is not listed in CISA KEV, which suggests a lower publicly documented exploitation probability. Still, the denial of service impact can disrupt business operations, especially for services that rely heavily on SWF processing. The absence of official patches in the provided data emphasizes the need to assess whether client systems are using the vulnerable library and to take mitigations accordingly.

Generated by OpenCVE AI on October 8, 2026 at 22:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade libming to a release that includes the fix (any newer stable version).
  • Limit processing of SWF files from untrusted sources by isolating the parsing component in a sandboxed environment or by implementing strict input validation and size limits before invoking libming functions.
  • Monitor the application for unexpected crashes or restarts; configure alerting on crash logs or error messages that indicate denial of service events.

Generated by OpenCVE AI on October 8, 2026 at 22:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 22:30:00 +0000

Type Values Removed Values Added
Title Denial of Service via Faulty SWF File Parsing in libming
Weaknesses CWE-122
CWE-20

Thu, 08 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Description An issue in libming through 0.4.8 allows a remote attacker to cause a denial of service via the readtag_file() in src/blocks/fromswf.c.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-08T20:15:45.168Z

Reserved: 2026-09-22T00:00:00.000Z

Link: CVE-2026-95116

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T21:18:03.740

Modified: 2026-10-08T21:33:42.423

Link: CVE-2026-95116

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T22:15:19Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow

  • CWE-20

    Improper Input Validation