Debian LTS: DLA-1133-1: ming security update
Summary
CVE-2017-11704
Heap-based buffer over-read in the function decompileIF in util/decompile.c
in Ming <= 0.4.8, which allows attackers to cause a denial of service via a
crafted file.
CVE-2017-11728
Heap-based buffer over-read in the function OpCode (called from
decompileSETMEMBER) in util/decompile.c in Ming <= 0.4.8, which allows
attackers to cause a denial of service via a crafted file.
CVE-2017-11729
Heap-based buffer over-read in the function OpCode (called from
decompileINCR_DECR line 1440) in util/decompile.c in Ming <= 0.4.8, which
allows attackers to cause a denial of service via a crafted file.
CVE-2017-11730
Heap-based buffer over-read in the function OpCode (called from
decompileINCR_DECR line 1474) in util/decompile.c in Ming <= 0.4.8, which
allows attackers to cause a denial of service via a crafted file.
CVE-2017-11731
Invalid memory read in the function OpCode (called from isLogicalOp and
decompileIF) in util/decompile.c in Ming <= 0.4.8, which allows attackers to cause a denial of service via a crafted file.
CVE-2017-11734
Heap-based buffer over-read in the function decompileCALLFUNCTION in
util/decompile.c in Ming <= 0.4.8, which allows attackers to cause a denial of
ser...