Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora Core 2: 2004-239 Critical: Libpng Buffer Overflow Risks

fedora
Calendar Grey August 11, 2004
Dist Fedora Esm H88
Addressing libjpeg flaws that may lead to integer overflows and potential system failures in Ubuntu. Make sure to upgrade promptly for enhanced protection!
This patch fixes numerous buffer overflow and pointer dereference vulnerabilities that a security audit turned up in libpng 1.2.x

Summary

The libpng package contains a library of functions for creating and

manipulating PNG (Portable Network Graphics) image format files. PNG

is a bit-mapped graphics format similar to the GIF format. PNG was

created to replace the GIF format, since GIF uses a patented data

compression algorithm.

Libpng should be installed if you need to manipulate PNG format image

files.

The libpng package contains a library of functions for creating and

manipulating PNG (Portable Network Graphics) image format files. PNG

is a bit-mapped graphics format similar to the GIF format. PNG was

created to replace the GIF format, since GIF uses a patented data

compression algorithm.

Libpng should be installed if you need to manipulate PNG format image

files.

Update Information:

The libpng package contains a library of functions for creating and manipulating PNG (Portable Network Graphics) image format files.

During a source code audit, Chris Evans discovered several buffer overflows in libpng. An attacker could create a carefully crafted PNG file in such a way that it would cause an application linked with libpng to execute arbitrary code when the file was opened by a victim. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0597 to these issues.

In addition, this audit discovered a potential NULL pointer dereference in libpng (CAN-2004-0598) and several integer overflow issues (CAN-2004-0599). An attacker could create a carefully crafted PNG file in such a way that it would cause an application linked with libpng to crash when the file was opened by the victim.

Red Hat would like to thank Chris Evans for discovering these issues.

* Fri Jul 23 2004 Matthias Clasen <mclasen@redhat.com> 2:1.2.5-8

- Build f...

Read the Full Advisory

Change Log

References

CORE 2:
Fedora Update Notification FEDORA-2004-239 2004-08-04
Product : Fedora Core 2 Name : libpng Version : 1.2.5 Release : 8 Summary : A library of functions for manipulating PNG image format files. Description : The libpng package contains a library of functions for creating and manipulating PNG (Portable Network Graphics) image format files. PNG is a bit-mapped graphics format similar to the GIF format. PNG was created to replace the GIF format, since GIF uses a patented data compression algorithm.
Libpng should be installed if you need to manipulate PNG format image files.

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora Core 2
Name: libpng
Version: 1.2.5
Release: 8
Summary: A library of functions for manipulating PNG image format
Product: Fedora Core 1
Name: libpng
Version: 1.2.5
Release: 7
Summary: A library of functions for manipulating PNG image format

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here