Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Debian DSA-1750-1 High Severity Libpng Denial Of Service Issue

debian
Calendar Grey March 22, 2009
Debian Logo
Enhance libpng promptly to address numerous discovered vulnerabilities that may compromise your system's safety.
Several vulnerabilities have been discovered in libpng, a library for reading and writing PNG files

Summary

Several vulnerabilities have been discovered in libpng, a library for
reading and writing PNG files. The Common Vulnerabilities and
Exposures project identifies the following problems:

The png_handle_tRNS function allows attackers to cause a denial of
service (application crash) via a grayscale PNG image with a bad tRNS
chunk CRC value. (CVE-2007-2445)

Certain chunk handlers allow attackers to cause a denial of service
(crash) via crafted pCAL, sCAL, tEXt, iTXt, and ztXT chunking in PNG
images, which trigger out-of-bounds read operations. (CVE-2007-5269)

libpng allows context-dependent attackers to cause a denial of service
(crash) and possibly execute arbitrary code via a PNG file with zero
length "unknown" chunks, which trigger an access of uninitialized
memory. (CVE-2008-1382)

The png_check_keyword might allow context-dependent attackers to set the
value of an arbitrary memory location to zero via vectors involving
creation of crafted PNG files with keywords. (CVE-2008-5907)

A memory leak in the...

Read the Full Advisory

Package: libpng

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here