Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 678804 (CVE-2019-9113, CVE-2019-9114) - media-libs/ming: multiple vulnerabilities
Summary: media-libs/ming: multiple vulnerabilities
Status: RESOLVED FIXED
Alias: CVE-2019-9113, CVE-2019-9114
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B3 [noglsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2019-02-26 06:16 UTC by D'juan McDonald (domhnall)
Modified: 2019-09-06 21:56 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description D'juan McDonald (domhnall) 2019-02-26 06:16:39 UTC
(https://nvd.nist.gov/vuln/detail/CVE-2019-9113):
Ming (aka libming) 0.4.8 has a NULL pointer dereference in the function getString() in the decompile.c file in libutil.a.

Upstream Reference: https://github.com/libming/libming/issues/171

(https://nvd.nist.gov/vuln/detail/CVE-2019-9114):
Ming (aka libming) 0.4.8 has an out of bounds write vulnerability in the function strcpyext() in the decompile.c file in libutil.a.

Upstream Reference: https://github.com/libming/libming/issues/170



Gentoo Security Padawan
(domhnall)
Comment 1 Aaron Bauman (RETIRED) gentoo-dev 2019-04-05 01:22:02 UTC
Neither are fixed yet as of 20181112 upstream.
Comment 2 Larry the Git Cow gentoo-dev 2019-08-04 19:36:33 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=f85984054ed9f49d7245234ee6aa9e737607f148

commit f85984054ed9f49d7245234ee6aa9e737607f148
Author:     Aaron Bauman <bman@gentoo.org>
AuthorDate: 2019-08-04 19:29:04 +0000
Commit:     Aaron Bauman <bman@gentoo.org>
CommitDate: 2019-08-04 19:29:04 +0000

    profiles/package.mask: add media-libs/ming
    
    Bug: https://bugs.gentoo.org/626412
    Bug: https://bugs.gentoo.org/650006
    Bug: https://bugs.gentoo.org/651574
    Bug: https://bugs.gentoo.org/661152
    Bug: https://bugs.gentoo.org/678804
    
    Signed-off-by: Aaron Bauman <bman@gentoo.org>

 profiles/package.mask | 5 +++++
 1 file changed, 5 insertions(+)
Comment 3 Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2019-09-06 07:23:51 UTC
The package has been removed.