Incorrect Conversion between Numeric Types in libming and Debian Linux - CVE-2018-5251
Published: January 5, 2018 / Updated: August 8, 2020
Debian
libming
Debian Linux
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
In libming 0.4.8, there is an integer signedness error vulnerability (left shift of a negative value) in the readSBits function (util/read.c). Remote attackers can leverage this vulnerability to cause a denial of service via a crafted swf file.