-------------------------------------------------------------------------Debian LTS Advisory DLA-3032-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/                      Markus Koschany
May 29, 2022                                  https://wiki.debian.org/LTS
-------------------------------------------------------------------------Package        : pngcheck
Version        : 2.3.0-7+deb9u1
CVE ID         : CVE-2020-27818
Debian Bug     : 976350

A flaw was found in the check_chunk_name() function of pngcheck, a tool to 
verify the integrity of PNG, JNG and MNG files. This flaw allows an attacker
who can pass a malicious file to be processed by pngcheck to cause a temporary
denial of service.

For Debian 9 stretch, this problem has been fixed in version
2.3.0-7+deb9u1.

We recommend that you upgrade your pngcheck packages.

For the detailed security status of pngcheck please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/pngcheck

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Debian LTS: DLA-3032-1: pngcheck security update

May 29, 2022
A flaw was found in the check_chunk_name() function of pngcheck, a tool to  verify the integrity of PNG, JNG and MNG files

Summary

We recommend that you upgrade your pngcheck packages.

For the detailed security status of pngcheck please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/pngcheck

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
-------------------------------------------------------------------------Package : pngcheck
Version : 2.3.0-7+deb9u1
CVE ID : CVE-2020-27818
Debian Bug : 976350

Related News