CRITICAL🇵🇱 Wersja polska

CVE-2023-50628

CVSS 9.8v3.1pub. 2023-12-20upd. 2024-11-21

Buffer Overflow vulnerability in libming version 0.4.8, allows attackers to execute arbitrary code and obtain sensitive information via parser.c component.

🤖 AI Analysis
How it works

The vulnerability is a buffer overflow (CWE-120) in the parser.c component of the Libming library. An attacker can supply crafted input data that causes a write beyond the boundaries of the allocated buffer in memory. This leads to overwriting critical data structures or return addresses, enabling the attacker to take control of the program execution flow.

Impact

An attacker can execute arbitrary code (RCE) in the context of a process using the vulnerable library and gain access to sensitive information processed by the application. Depending on the process privileges, complete system takeover is possible.

Mitigation & patch

Patches available from the vendor should be applied according to the references — fix available as pull request #290 in the Libming project GitHub repository

Who is affected

Libming version 0.4.8

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Libming

    APP
    Libming
    0.4.8
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEMemory
CWE
References

Related vulnerabilities

CVE-2020-11894CRITICAL9.1PL ✓same product

Heap-based buffer over-read w libming 0.4.8 — funkcja decompileIF()

CVE-2020-11895CRITICAL9.1PL ✓same product

Heap-based buffer over-read w libming 0.4.8 — funkcja decompileIF()

CVE-2019-16705CRITICAL9.1PL ✓same product

Out-of-bounds read w libming 0.4.8 — funkcja OpCode() w decompile.c

CVE-2025-66869HIGH7.5same product

Buffer overflow vulnerability in function strcat in asan_interceptors.cpp in libming 0.4.8.

CVE-2025-66877HIGH7.5same product

Buffer overflow vulnerability in function dcputchar in decompile.c in libming 0.4.8.