CVE-2017-11731 — Out-of-bounds Read in Ming
Severity
5.5MEDIUMNVD
EPSS
0.2%
top 57.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 29
Latest updateMay 14
Description
An invalid memory read vulnerability was found in the function OpCode (called from isLogicalOp and decompileIF) in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.
CVSS vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6
Affected Packages1 packages
🔴Vulnerability Details
2GHSAâ–¶
GHSA-8q27-xc9c-9wjr: An invalid memory read vulnerability was found in the function OpCode (called from isLogicalOp and decompileIF) in util/decompile↗2022-05-14
OSVâ–¶
CVE-2017-11731: An invalid memory read vulnerability was found in the function OpCode (called from isLogicalOp and decompileIF) in util/decompile↗2017-07-29