Debian Bug report logs - #892260
Several vulnerabilities in the latest libming(0.4.8),confirm please.

Package: src:ming; Maintainer for src:ming is (unknown);

Reported by: New Zone <fantasy7082@hotmail.com>

Date: Wed, 7 Mar 2018 10:15:02 UTC

Severity: normal

Done: Adrian Bunk <bunk@debian.org>

Bug is archived. No further changes may be made.

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, unknown-package@qa.debian.org:
Bug#892260; Package libming. (Wed, 07 Mar 2018 10:15:07 GMT) (full text, mbox, link).


Acknowledgement sent to New Zone <fantasy7082@hotmail.com>:
New Bug report received and forwarded. Copy sent to unknown-package@qa.debian.org. (Wed, 07 Mar 2018 10:15:07 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: New Zone <fantasy7082@hotmail.com>
To: "submit@bugs.debian.org" <submit@bugs.debian.org>
Subject: Several vulnerabilities in the latest libming(0.4.8),confirm please.
Date: Wed, 7 Mar 2018 10:12:10 +0000
[Message part 1 (text/plain, inline)]
Package: libming
Version: 0.4.8
project link: https://github.com/libming/libming/<https://github.com/pts/sam2p>

There are several vulnerabilites in libming 0.4.8, like heap-based buffer overflows, null pointer dereference  have been found. All of them can lead to a denial of service attack.

the details of vulnerabilites are below links:
https://github.com/libming/libming/issues/109
https://github.com/libming/libming/issues/110<https://github.com/libming/libming/issues/10>
https://github.com/libming/libming/issues/111<https://github.com/libming/libming/issues/10>
https://github.com/libming/libming/issues/112<https://github.com/libming/libming/issues/10>
https://github.com/libming/libming/issues/113<https://github.com/libming/libming/issues/1>
https://github.com/libming/libming/issues/114<https://github.com/libming/libming/issues/1>
https://github.com/libming/libming/issues/115<https://github.com/libming/libming/issues/10>
https://github.com/libming/libming/issues/116<https://github.com/libming/libming/issues/10>
https://github.com/libming/libming/issues/117<https://github.com/libming/libming/issues/10>
https://github.com/libming/libming/issues/118<https://github.com/libming/libming/issues/1>
https://github.com/libming/libming/issues/119<https://github.com/libming/libming/issues/10>
https://github.com/libming/libming/issues/120<https://github.com/libming/libming/issues/10><https://github.com/libming/libming/issues/10>
<https://github.com/libming/libming/issues/10><https://github.com/libming/libming/issues/1>
<https://github.com/libming/libming/issues/10><https://github.com/libming/libming/issues/10>

I am using Debian 7.5 "Wheezy", libc.7 ,gcc 5.4.0.


name:liu zhu
mail:fantasy7082@hotmail.com

[Message part 2 (text/html, inline)]

Reply sent to Adrian Bunk <bunk@debian.org>:
You have taken responsibility. (Thu, 08 Mar 2018 12:03:06 GMT) (full text, mbox, link).


Notification sent to New Zone <fantasy7082@hotmail.com>:
Bug acknowledged by developer. (Thu, 08 Mar 2018 12:03:06 GMT) (full text, mbox, link).


Message #10 received at 892260-done@bugs.debian.org (full text, mbox, reply):

From: Adrian Bunk <bunk@debian.org>
To: 892260-done@bugs.debian.org
Subject: ming is not in any supported non-LTS Debian release
Date: Thu, 8 Mar 2018 13:59:26 +0200
ming is not in any supported non-LTS Debian release:
  https://tracker.debian.org/pkg/ming

If there are any vulnerabilities left that are not fix,
please discuss with the LTS team at debian-lts@lists.debian.org

cu
Adrian

-- 

       "Is there not promise of rain?" Ling Tan asked suddenly out
        of the darkness. There had been need of rain for many days.
       "Only a promise," Lao Er said.
                                       Pearl S. Buck - Dragon Seed




Bug reassigned from package 'libming' to 'src:ming'. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Thu, 08 Mar 2018 21:30:06 GMT) (full text, mbox, link).


No longer marked as found in versions 0.4.8. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Thu, 08 Mar 2018 21:30:07 GMT) (full text, mbox, link).


Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Fri, 06 Apr 2018 07:28:57 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Sun Apr 20 14:21:00 2025; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU General Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.