Debian Security Advisory

DLA-890-1 ming -- LTS security update

Date Reported:
10 Apr 2017
Affected Packages:
ming
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2017-7578.
More information:

It was discovered that there were multiple heap-based buffer overflows in ming, a library to generate SWF (Flash) files.

The updated packages prevent a crash in the listswf utility due to a heap-based buffer overflow in the parseSWF_RGBA function and several other functions in parser.c.

AddressSanitizer flagged them as invalid writes of size 1 but the heap could be written to multiple times. The overflows are caused by a pointer behind the bounds of a statically allocated array of structs of type SWF_GRADIENTRECORD.

For Debian 7 Wheezy, this issue has been fixed in ming version 1:0.4.4-1.1+deb7u2.

We recommend that you upgrade your ming packages.