-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Mon, 10 Apr 2017 13:23:29 +0100 Source: ming Binary: libming1 libming-dev ming-fonts-dejavu ming-fonts-opensymbol libswf-perl libming-util python-ming php5-ming Architecture: source amd64 all Version: 1:0.4.4-1.1+deb7u2 Distribution: wheezy-security Urgency: high Maintainer: Stuart R. Anderson <anderson@netsweng.com> Changed-By: Chris Lamb <lamby@debian.org> Description: libming-dev - Library to generate SWF (Flash) Files (development files) libming-util - Library to generate SWF (Flash) Files - Utilities libming1 - Library to generate SWF (Flash) Files libswf-perl - Ming (SWF) module for Perl ming-fonts-dejavu - Ming format DejaVue Fonts ming-fonts-opensymbol - Ming format Opensymbol Fonts php5-ming - Ming module for php5 python-ming - Ming (SWF) module for Python Changes: ming (1:0.4.4-1.1+deb7u2) wheezy-security; urgency=high . * CVE-2017-7578: Prevent a crash in the listswf utility due to a heap-based buffer overflow in the parseSWF_RGBA function and several other functions in parser.c. . AddressSanitizer flags them as invalid writes "of size 1" but the heap could be written to multiple times. The overflows are caused by a pointer behind the bounds of a statically allocated array of structs of type SWF_GRADIENTRECORD. Checksums-Sha1: 232853effac353a0c53ac79c7d31cdfb73c7c125 2362 ming_0.4.4-1.1+deb7u2.dsc d2a684e743f30ff7416580904a3eb1c47e0ecf52 14838911 ming_0.4.4.orig.tar.gz 39d476a6788d9bcf4394779efc77529dff854e5d 24536 ming_0.4.4-1.1+deb7u2.diff.gz 3fb3f829ea4139d5063aa9d901371f4b34a81d87 186338 libming1_0.4.4-1.1+deb7u2_amd64.deb a09c254bde269ec04163f9a6b3491d0de34437a0 240576 libming-dev_0.4.4-1.1+deb7u2_amd64.deb 5fd9eb3e4839922e82760200677b8fb131d0e26c 212624 libswf-perl_0.4.4-1.1+deb7u2_amd64.deb e24c6ae20877179dd92a2e7bb76f8cb8fc71264a 711068 libming-util_0.4.4-1.1+deb7u2_amd64.deb a9e69820cd82d14e4091e344e600de50092c6547 166568 python-ming_0.4.4-1.1+deb7u2_amd64.deb 1f15c8bde5eea53fd11e25d52a960ce02f7fc8f3 54326 php5-ming_0.4.4-1.1+deb7u2_amd64.deb 27e986f9d8f24f492246c25e49f1915c162f0730 36618 ming-fonts-dejavu_0.4.4-1.1+deb7u2_all.deb b6ee134b3b9ac6d976fe65fdf4c0fd40fb88eaf6 5650 ming-fonts-opensymbol_0.4.4-1.1+deb7u2_all.deb Checksums-Sha256: 5959f6737b1f9a41aa0ebd383be19243d47572c8a9a08779e0cd99b60ace42b6 2362 ming_0.4.4-1.1+deb7u2.dsc a9ab92d64cefdf42780c52b71e21e632f5bea211824c99c23dac9761003d969a 14838911 ming_0.4.4.orig.tar.gz f63f8ef235c681c55c22938a5cb8b67fc83514fbcf7421d5da9e48fa01de2f95 24536 ming_0.4.4-1.1+deb7u2.diff.gz e9d59f649a95532645098728cc5b8dbf386d7b8eaae614b5678404ff66575a11 186338 libming1_0.4.4-1.1+deb7u2_amd64.deb 64d7b362603593d2a8080b13094024aaaaeb7a68470c6565cee4411a5759c48f 240576 libming-dev_0.4.4-1.1+deb7u2_amd64.deb 777d698405aae7cbb105f018602698e1ecfe98bae3fe7541d936e10e6fa48f73 212624 libswf-perl_0.4.4-1.1+deb7u2_amd64.deb bf8cf445dfe61cd28f71a7e52335a52356ac2d4a924d32fd71993b2922525238 711068 libming-util_0.4.4-1.1+deb7u2_amd64.deb 970b75c49dda4fcb486fc9123557391b9d762f6b15f070cf59198877424bb0d7 166568 python-ming_0.4.4-1.1+deb7u2_amd64.deb eae784e7c2104b8380011e128a5b74a8dacecdaceac6fbc798f8a9c2daa7e52b 54326 php5-ming_0.4.4-1.1+deb7u2_amd64.deb 7a8d4c4cd37f4f3375d507994d1808fca99e9f635f16cdde14dbac853912a76a 36618 ming-fonts-dejavu_0.4.4-1.1+deb7u2_all.deb b86200059e94a8efc447dd025a6b3ecd6c9bbdabd73b92d15051d39ee8d9fe98 5650 ming-fonts-opensymbol_0.4.4-1.1+deb7u2_all.deb Files: 608307b594f24f4e0ea1f766e2d82bfb 2362 libs optional ming_0.4.4-1.1+deb7u2.dsc d8e75796f3ee9b9a0b582787283435cb 14838911 libs optional ming_0.4.4.orig.tar.gz 50b4c8de2bc1478f51f191c274dbfaf6 24536 libs optional ming_0.4.4-1.1+deb7u2.diff.gz 07b53c720d84222ff241df68d2a42d65 186338 libs optional libming1_0.4.4-1.1+deb7u2_amd64.deb 878298e45d486ca17a5397d2f82f368b 240576 libdevel optional libming-dev_0.4.4-1.1+deb7u2_amd64.deb 0161066b36526824cbff8a246eb82d12 212624 perl optional libswf-perl_0.4.4-1.1+deb7u2_amd64.deb a7c20a62766087d335f7902dc98259b7 711068 devel optional libming-util_0.4.4-1.1+deb7u2_amd64.deb e9d17d8cacf8018d70cabcd6e4ae439b 166568 python optional python-ming_0.4.4-1.1+deb7u2_amd64.deb d29137ed115315ba4f216261d77bea04 54326 web optional php5-ming_0.4.4-1.1+deb7u2_amd64.deb 6a99974e58a6cde9c6e369c10db65d36 36618 web optional ming-fonts-dejavu_0.4.4-1.1+deb7u2_all.deb 6dd34b880c916a1a989f796e8b32004d 5650 web optional ming-fonts-opensymbol_0.4.4-1.1+deb7u2_all.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAljre0kACgkQHpU+J9Qx HljorBAAkjcZvKUw61kVIWnRTCrlwoUmEXLHqmxLnk82nACnAPtZ6vEpLjKlMvaY 6XTeyrzeDGF6mussENfJSA9n9N7Tcx6UqIAecGkyc7KaqyS+A8niYNcKq+aN1Re0 EnsairphOlpV2yFzcoDWBsZpDAV1pTGgHpfzPG1wKISqDGI08b84XXT86R4vSOsx G5ZE15aKWcRvC7ArQitGPbGMGdkfatLOg+g6baQ9JjN34wgh4hJiyBGMdwdR+0YQ joZq/oq6zkUMpczioaMXSfYs6b2QKp30+nwITbUlwTqnE5ysyTqTS1c7GpLrDhGo oeeF7YCuexJrgYrl9EEZItU6sEWfj8xorc1TFtFWXQyfivHfnXLCGmrPhri1ukYC VXKXFxfkI6AU4/CpAdo3RusqbG2wwefxnclxwUhOTENjijVARvhBnmECz9zZahUe iCEVmqw9xSBRrykERzWoVCsxTtBfVyEruxUMkVpmA3Ux3SpgVdS65hNkflN6F3H8 br/WFAra3M9wOSsTRCmNkAGrOIr/sVBuGvhR+Y+BLXM9O9OMZoWBZSuTu0qoJgsJ w6n27y/2UoU706Za/7i/Rkr4Qr4ntS5WY6QCs+5oSvaL+el6NdwKeLX7vjgDvMZw SlwswTxkx50myeVKIuHu17ihlKtyZZRhtPFd2m4bnYq/K/+r1jg= =If/u -----END PGP SIGNATURE-----