The readEncUInt30 function in util/read.c in libming 0.4.8 mishandles memory allocation. A crafted input will lead to a remote denial of service (NULL pointer dereference) attack against parser.c.
| Software | From | Fixed in |
|---|---|---|
| libming / libming | 0.4.8 | 0.4.8.x |
| debian / debian_linux | 7.0 | 7.0.x |