CVE-2017-11731 — Out-of-bounds Read in Ming

Severity
5.5MEDIUMNVD
EPSS
0.2%
top 57.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 29
Latest updateMay 14

Description

An invalid memory read vulnerability was found in the function OpCode (called from isLogicalOp and decompileIF) in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages1 packages

â–¶NVDlibming/ming0.4.8

🔴Vulnerability Details

2
GHSA
GHSA-8q27-xc9c-9wjr: An invalid memory read vulnerability was found in the function OpCode (called from isLogicalOp and decompileIF) in util/decompile↗2022-05-14
â–¶
OSV
CVE-2017-11731: An invalid memory read vulnerability was found in the function OpCode (called from isLogicalOp and decompileIF) in util/decompile↗2017-07-29
â–¶

💬Community

2
Bugzilla
CVE-2017-11728 CVE-2017-11729 CVE-2017-11730 CVE-2017-11731 CVE-2017-11732 CVE-2017-11733 CVE-2017-11734 CVE-2017-16898 ming: various flaws [fedora-all]↗2017-07-31
â–¶
Bugzilla
CVE-2017-11731 ming: invalid memory read in OpCode via isLogicalOp and decompileIF↗2017-07-31
â–¶
CVE-2017-11731 — Out-of-bounds Read in Libming Ming | cvebase