Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Fedora Core 2: FEDORA-2004-238 Critical: libpng Buffer Overflow

fedora
Calendar Grey August 11, 2004
Dist Fedora Esm H88
Recent vulnerabilities in libpng have been uncovered, which may result in buffer overflow complications and additional risks on Fedora operating systems.
Multiple libpng vulnerabilities are backpatched to the old 1.0.x libpng libraries.

Summary

The libpng10 package contains an old version of libpng, a library of

functions for creating and manipulating PNG (Portable Network Graphics)

image format files.

This package is needed if you want to run binaries that were linked

dynamically

with libpng 1.0.x.

The libpng10 package contains an old version of libpng, a library of

functions for creating and manipulating PNG (Portable Network Graphics)

image format files.

This package is needed if you want to run binaries that were linked

dynamically with libpng 1.0.x.

Update Information:

The libpng package contains a library of functions for creating and manipulating PNG (Portable Network Graphics) image format files.

During a source code audit, Chris Evans discovered several buffer overflows in libpng. An attacker could create a carefully crafted PNG file in such a way that it would cause an application linked with libpng to execute arbitrary code when the file was opened by a victim. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0597 to these issues.

In addition, this audit discovered a potential NULL pointer dereference in libpng (CAN-2004-0598) and several integer overflow issues (CAN-2004-0599). An attacker could create a carefully crafted PNG file in such a way that it would cause an application linked with libpng to crash when the file was opened by the victim.

Red Hat would like to thank Chris Evans for discovering these issues.

* Fri Jul 23 2004 Matthias Clasen <mclasen@redhat.com> 1.0.15-8

- Build fo...

Read the Full Advisory

Change Log

References

CORE 2:
Fedora Update Notification FEDORA-2004-238 2004-08-04
Product : Fedora Core 2 Name : libpng10 Version : 1.0.15 Release : 8 Summary : Old version of libpng, needed to run old binaries. Description : The libpng10 package contains an old version of libpng, a library of functions for creating and manipulating PNG (Portable Network Graphics) image format files.
This package is needed if you want to run binaries that were linked dynamically with libpng 1.0.x.

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora Core 2
Name: libpng10
Version: 1.0.15
Release: 8
Summary: Old version of libpng, needed to run old binaries.
Product: Fedora Core 1
Name: libpng10
Version: 1.0.15
Release: 7
Summary: Old version of libpng, needed to run old binaries.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here