Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Debian 5.0: DSA-2072-1 Critical: Libpng Memory Leak And DoS

debian
Calendar Grey July 19, 2010
Debian Logo
Debian has published advisory DSA-2072-1 concerning libpng, tackling various security vulnerabilities such as a potential buffer overflow and memory leak.
Several vulnerabilities have been discovered in libpng, a library for reading and writing PNG files

Summary

Several vulnerabilities have been discovered in libpng, a library for
reading and writing PNG files. The Common Vulnerabilities and
Exposures project identifies the following problems:

CVE-2010-1205

It was discovered a buffer overflow in libpng which allows remote
attackers to execute arbitrary code via a PNG image that triggers
an additional data row.


CVE-2010-2249

It was discovered a memory leak in libpng which allows remote
attackers to cause a denial of service (memory consumption and
application crash) via a PNG image containing malformed Physical
Scale (aka sCAL) chunks


For the stable distribution (lenny), these problems have been fixed in
version 1.2.27-2+lenny4.

For the testing (squeeze) and unstable (sid) distribution, these
problems have been fixed in version 1.2.44-1

We recommend that you upgrade your libpng package.

Upgrade instructions
- --------------------

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If ...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: libpng

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here