Debian Security Advisory

DLA-1176-1 ming -- LTS security update

Date Reported:
18 Nov 2017
Affected Packages:
ming
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2017-9988, CVE-2017-9989, CVE-2017-11733.
More information:

Multiple vulnerabilities have been discovered in Ming:

  • CVE-2017-9988

    NULL pointer dereference in the readEncUInt30 function (util/read.c) in Ming <= 0.4.8, which allows attackers to cause a denial of service via a crafted file.

  • CVE-2017-9989

    NULL pointer dereference in the outputABC_STRING_INFO function (util/outputtxt.c) in Ming <= 0.4.8, which allows attackers to cause a denial of service via a crafted file.

  • CVE-2017-11733

    NULL pointer dereference in the stackswap function (util/decompile.c) in Ming <= 0.4.8, which allows attackers to cause a denial of service via a crafted file.

For Debian 7 Wheezy, these problems have been fixed in version 1:0.4.4-1.1+deb7u5.

We recommend that you upgrade your ming packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS