Ming (aka libming) 0.4.8 has a heap buffer overflow and underflow in the decompileCAST function in util/decompile.c in libutil.a. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted SWF file.
[
{
"signature_type": "Function",
"target": {
"file": "util/decompile.c",
"function": "decompileAction"
},
"deprecated": false,
"source": "https://github.com/libming/libming/commit/da9d86eab55cbf608d5c916b8b690f5b76bca462",
"id": "CVE-2019-12982-8dae06fc",
"signature_version": "v1",
"digest": {
"function_hash": "25518960770951097210511730068977518012",
"length": 6378.0
}
},
{
"signature_type": "Line",
"target": {
"file": "util/decompile.c"
},
"deprecated": false,
"source": "https://github.com/libming/libming/commit/da9d86eab55cbf608d5c916b8b690f5b76bca462",
"id": "CVE-2019-12982-9bf76232",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"291806668453285032842876143386896285226",
"50565243544623631078359617180815708249",
"40959230763940810433426747898058331203",
"176944563267413473422621745067033536982",
"189599252662372782692483801181893286226",
"267489013656535968785972135318874133504",
"149269957849605303310475787259581532401",
"196299519539401434255969427334715340866"
]
}
}
]