Backport security fixes from [PR#145](https://github.com/libming/libming/pull/145) Fixes: CVE-2018-7866, CVE-2018-7873, CVE-2018-7876, CVE-2018-9009, CVE-2018-9132. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-a1b6fc5274 2019-10-26 17:17:38.267507 --------------------------------------------------------------------------------Name : ming Product : Fedora 31 Version : 0.4.9 Release : 0.4.20181112git5009802.fc31 URL : Summary : A library for generating Macromedia Flash files Description : Ming is a library for generating Macromedia Flash files (.swf), written in C, and includes useful utilities for working with .swf files. --------------------------------------------------------------------------------Update Information: Backport security fixes from [PR#145](https://github.com/libming/libming/pull/145) Fixes: CVE-2018-7866, CVE-2018-7873, CVE-2018-7876, CVE-2018-9009, CVE-2018-9132 --------------------------------------------------------------------------------ChangeLog: * Wed Oct 2 2019 Dominik Mierzejewski - 0.4.9-0.4.20181112git5009802 - backport security fixes from PR#145 - fixes: CVE-2018-7866, CVE-2018-7873, CVE-2018-7876, CVE-2018-9009, CVE-2018-9132 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-a1b6fc5274' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Backport security fixes from [PR#145](https://github.com/libming/libming/pull/145) Fixes: CVE-2018-7866, CVE-2018-7873, CVE-2018-7876, CVE-2018-9009, CVE-2018-9132. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-03aa4f746c 2019-10-12 01:28:44.976276 --------------------------------------------------------------------------------Name : ming Product : Fedora 29 Version : 0.4.9 Release : 0.2.20181112git5009802.fc29 URL : Summary : A library for generating Macromedia Flash files Description : Ming is a library for generating Macromedia Flash files (.swf), written in C, and includes useful utilities for working with .swf files. --------------------------------------------------------------------------------Update Information: Backport security fixes from [PR#145](https://github.com/libming/libming/pull/145) Fixes: CVE-2018-7866, CVE-2018-7873, CVE-2018-7876, CVE-2018-9009, CVE-2018-9132 --------------------------------------------------------------------------------ChangeLog: * Wed Oct 2 2019 Dominik Mierzejewski - 0.4.9-0.2.20181112git5009802 - backport security fixes from PR#145 - fixes: CVE-2018-7866, CVE-2018-7873, CVE-2018-7876, CVE-2018-9009, CVE-2018-9132 * Mon Feb 25 2019 Dominik Mierzejewski - 0.4.9-0.1.20181112git5009802 - sync with upstream git - fixes: CVE-2018-6358, CVE-2018-7867, CVE-2018-7868, CVE-2018-7870, CVE-2018-7871, CVE-2018-7872, CVE-2018-7875, CVE-2018-9165 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-03aa4f746c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Backport security fixes from [PR#145](https://github.com/libming/libming/pull/145) Fixes: CVE-2018-7866, CVE-2018-7873, CVE-2018-7876, CVE-2018-9009, CVE-2018-9132. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-5139453028 2019-10-12 00:23:35.069652 --------------------------------------------------------------------------------Name : ming Product : Fedora 30 Version : 0.4.9 Release : 0.2.20181112git5009802.fc30 URL : Summary : A library for generating Macromedia Flash files Description : Ming is a library for generating Macromedia Flash files (.swf), written in C, and includes useful utilities for working with .swf files. --------------------------------------------------------------------------------Update Information: Backport security fixes from [PR#145](https://github.com/libming/libming/pull/145) Fixes: CVE-2018-7866, CVE-2018-7873, CVE-2018-7876, CVE-2018-9009, CVE-2018-9132 --------------------------------------------------------------------------------ChangeLog: * Wed Oct 2 2019 Dominik Mierzejewski - 0.4.9-0.2.20181112git5009802 - backport security fixes from PR#145 - fixes: CVE-2018-7866, CVE-2018-7873, CVE-2018-7876, CVE-2018-9009, CVE-2018-9132 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-5139453028' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Multiple vulnerabilities have been found in Ming, the worst of which could result in a Denial of Service condition.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201904-24 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Ming: Multiple vulnerabilities Date: April 24, 2019 Bugs: #624712, #626498, #646770 ID: 201904-24 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in Ming, the worst of which could result in a Denial of Service condition. Background ========= A library for generating Macromedia Flash files. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-libs/ming < 0.20181112 > = 0.20181112 Description ========== Multiple vulnerabilities have been discovered in Ming. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All Ming users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-libs/ming-0.20181112" References ========= [ 1 ] CVE-2017-11728 https://nvd.nist.gov/vuln/detail/CVE-2017-11728 [ 2 ] CVE-2017-11729 https://nvd.nist.gov/vuln/detail/CVE-2017-11729 [ 3 ] CVE-2017-11730 https://nvd.nist.gov/vuln/detail/CVE-2017-11730 [ 4 ] CVE-2017-11731 https://nvd.nist.gov/vuln/detail/CVE-2017-11731 [ 5 ] CVE-2017-11732 https://nvd.nist.gov/vuln/detail/CVE-2017-11732 [ 6 ] CVE-2017-11733 https://nvd.nist.gov/vuln/detail/CVE-2017-11733 [ 7 ] CVE-2017-11734 https://nvd.nist.gov/vuln/detail/CVE-2017-11734 [ 8 ] CVE-2017-9988 https://nvd.nist.gov/vuln/detail/CVE-2017-9988 [ 9 ] CVE-2017-9989 https://nvd.nist.gov/vuln/detail/CVE-2017-9989 [ 10 ] CVE-2018-5251 https://nvd.nist.gov/vuln/detail/CVE-2018-5251 [ 11 ] CVE-2018-5294 https://nvd.nist.gov/vuln/detail/CVE-2018-5294 [ 12 ] CVE-2018-6315 https://nvd.nist.gov/vuln/detail/CVE-2018-6315 [ 13 ] CVE-2018-6358 https://nvd.nist.gov/vuln/detail/CVE-2018-6358 [ 14 ] CVE-2018-6359 https://nvd.nist.gov/vuln/detail/CVE-2018-6359 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201904-24 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Fixes: CVE-2018-6358, CVE-2018-7867, CVE-2018-7868, CVE-2018-7870, CVE-2018-7871, CVE-2018-7872, CVE-2018-7875, CVE-2018-9165.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-4fdf19459d 2019-03-06 15:27:20.805967 --------------------------------------------------------------------------------Name : ming Product : Fedora 28 Version : 0.4.9 Release : 0.1.20181112git5009802.fc28 URL : Summary : A library for generating Macromedia Flash files Description : Ming is a library for generating Macromedia Flash files (.swf), written in C, and includes useful utilities for working with .swf files. --------------------------------------------------------------------------------Update Information: Fixes: CVE-2018-6358, CVE-2018-7867, CVE-2018-7868, CVE-2018-7870, CVE-2018-7871, CVE-2018-7872, CVE-2018-7875, CVE-2018-9165. --------------------------------------------------------------------------------ChangeLog: * Mon Feb 25 2019 Dominik Mierzejewski - 0.4.9-0.1.20181112git5009802 - sync with upstream git - fixes: CVE-2018-6358, CVE-2018-7867, CVE-2018-7868, CVE-2018-7870, CVE-2018-7871, CVE-2018-7872, CVE-2018-7875, CVE-2018-9165 --------------------------------------------------------------------------------References: [ 1 ] Bug #1539898 - CVE-2018-6358 ming: Heap-based buffer overflow in printDefineFont2 function in util/listfdb.c https://bugzilla.redhat.com/show_bug.cgi?id=1539898 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-4fdf19459d' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Multiple vulnerabilities have been discovered in Ming: CVE-2018-7866 . Package : ming Version : 1:0.4.4-1.1+deb7u9 CVE ID : CVE-2018-7866 CVE-2018-7873 CVE-2018-7876 CVE-2018-9009 CVE-2018-9132 Multiple vulnerabilities have been discovered in Ming: CVE-2018-7866 NULL pointer dereference in the newVar3 function (util/decompile.c). Remote attackers might leverage this vulnerability to cause a denial of service via a crafted swf file. CVE-2018-7873 Heap-based buffer overflow vulnerability in the getString function (util/decompile.c). Remote attackers might leverage this vulnerability to cause a denial of service via a crafted swf file. CVE-2018-7876 Integer overflow and resulting memory exhaustion in the parseSWF_ACTIONRECORD function (util/parser.c). Remote attackers might leverage this vulnerability to cause a denial of service via a crafted swf file. CVE-2018-9009 Various heap-based buffer overflow vulnerabilites in util/decompiler.c. Remote attackers might leverage this vulnerability to cause a denial of service via a crafted swf file. CVE-2018-9132 NULL pointer dereference in the getInt function (util/decompile.c). Remote attackers might leverage this vulnerability to cause a denial of service via a crafted swf file. For Debian 7 "Wheezy", these problems have been fixed in version 1:0.4.4-1.1+deb7u9. We recommend that you upgrade your ming packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance your ming package to address several security flaws and mitigate denial of service threats.. ming Package, Debian LTS, Critical Security Fix, Remote Exploits. . Severity: Critical. LinuxSecurity.com Team
Multiple vulnerabilities have been discovered in Ming: CVE-2018-6358 . Package : ming Version : 0.4.4-1.1+deb7u8 CVE ID : CVE-2018-6358 CVE-2018-7867 CVE-2018-7868 CVE-2018-7870 CVE-2018-7871 CVE-2018-7872 CVE-2018-7875 CVE-2018-9165 Multiple vulnerabilities have been discovered in Ming: CVE-2018-6358 Heap-based buffer overflow vulnerability in the printDefineFont2 function (util/listfdb.c). Remote attackers might leverage this vulnerability to cause a denial of service via a crafted swf file. CVE-2018-7867 Heap-based buffer overflow vulnerability in the getString function (util/decompile.c) during a RegisterNumber sprintf. Remote attackers might leverage this vulnerability to cause a denial of service via a crafted swf file. CVE-2018-7868 Heap-based buffer over-read vulnerability in the getName function (util/decompile.c) for CONSTANT8 data. Remote attackers might leverage this vulnerability to cause a denial of service via a crafted swf file. CVE-2018-7870 Invalid memory address dereference in the getString function (util/decompile.c) for CONSTANT16 data. Remote attackers might leverage this vulnerability to cause a denial of service via a crafted swf file. CVE-2018-7871 Heap-based buffer over-read vulnerability in the getName function (util/decompile.c) for CONSTANT16 data. Remote attackers might leverage this vulnerability to cause a denial of service via a crafted swf file. CVE-2018-7872 Invalid memory address dereference in the getName function (util/decompile.c) for CONSTANT16 data. Remote attackers might leverage this vulnerability to cause a denial of service via a crafted swf file. CVE-2018-7875 Heap-based buffer over-read vulnerability in the getName function (util/decompile.c) for CONSTANT8 data. Remote attackers might leverage this vulnerability to cause a denial of service via a crafted swf file. CVE-2018-9165 The pushdup function (util/decompile.c)performs shallow copy of String elements (instead of deep copy), allowing simultaneous change of multiple elements of the stack, which indirectly makes the library vulnerable to a NULL pointer dereference in getName (util/decompile.c). Remote attackers might leverage this vulnerability to cause dos via a crafted swf file. For Debian 7 "Wheezy", these problems have been fixed in version 0.4.4-1.1+deb7u8. We recommend that you upgrade your ming packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance ming to address several critical flaws, such as memory overflow and service interruption vulnerabilities.. Ming Security Update, Debian LTS Security, Buffer Overflow Fix. . Severity: Critical. LinuxSecurity.com Team
Multiple vulnerabilities have been discovered in Ming: CVE-2018-5251 . Package : ming Version : 0.4.4-1.1+deb7u7 CVE ID : CVE-2018-5251 CVE-2018-5294 CVE-2018-6315 CVE-2018-6359 Multiple vulnerabilities have been discovered in Ming: CVE-2018-5251 Integer signedness error vulnerability (left shift of a negative value) in the readSBits function (util/read.c). Remote attackers can leverage this vulnerability to cause a denial of service via a crafted swf file. CVE-2018-5294 Integer overflow vulnerability (caused by an out-of-range left shift) in the readUInt32 function (util/read.c). Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted swf file. CVE-2018-6315 Integer overflow and resultant out-of-bounds read in the outputSWF_TEXT_RECORD function (util/outputscript.c). Remote attackers could leverage this vulnerability to cause a denial of service or unspecified other impact via a crafted SWF file. CVE-2018-6359 Use-after-free vulnerability in the decompileIF function (util/decompile.c). Remote attackers could leverage this vulnerability to cause a denial of service or unspecified other impact via a crafted SWF file. For Debian 7 "Wheezy", these problems have been fixed in version 0.4.4-1.1+deb7u7. We recommend that you upgrade your ming packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Several security issues identified in ming; users of Debian 7 Wheezy should consider upgrading to reduce potential threats.. Debian Ming Security, Vulnerability Management, Security Notice. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.