Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Fedora 25: ming Security Update: Critical Heap Overflow Fixes Included

fedora
Calendar Grey April 19, 2017
Dist Fedora Esm H88
The latest update for ming addresses several enhancements, including support for PHP7 and the resolution of vital security vulnerabilities such as buffer overflows.
Release 0.4.8 (no ABI or API changes) * Add PHP7 compatibility * Fix C++ output of disassembler * Fix heap overflows in parser.c (CVE-2017-7578) * Avoid division by zero in lis...

Summary

Ming is a library for generating Macromedia Flash files (.swf), written in C,

and includes useful utilities for working with .swf files.

Release 0.4.8 (no ABI or API changes) * Add PHP7 compatibility * Fix C++

output of disassembler * Fix heap overflows in parser.c (CVE-2017-7578) *

Avoid division by zero in listmp3 when no valid frame was found (CVE-2016-9265)

* Don't try printing unknown block (CVE-2016-9828) * Parse Protect tag's

Password as string (CVE-2016-9827) * Check values before deriving malloc

parameters from them in parser.c (CVE-2016-9829) * Make readString() stop

reading string past buffer's end * Return EOF when reading unsigned values

hits end of memory backed buffer * Exit immediately when unexpected EOF is by

fgetc() in utility programs (CVE-2016-9831) * Fix using EOF marker -1 value as

a valid flag byte (CVE-2016-9266) * Fix division by zero sample rate due to

global buffer overflow (CVE-2016-9264, CVE-2016-9265)

[ 1 ] Bug #1438687 - CVE-2016-9264 CVE-2016-9265 CVE-2016-9266 CVE-2016-9827 CVE-2016-9828 CVE-2016-9829 CVE-2016-9831 ming: Multiple security vulnerabilities [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1438687

su -c 'dnf upgrade ming' at the command line.

For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 25
Version: 0.4.8
Release: 1.fc25
URL: Summary : A library for generating Macromedia Flash files

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here